Natural language in. Governed SQL out. Nothing leaks.
The sidecar sits beside the warehouse, not inside the model. Classification is declared data in a catalogue table, enforcement is a database grant, and the model is a swappable component.
Five steps, every question
- 1Sign in
The same account and the same audit trail as the desktop client. No separate identity.
- 2Scope
Tick a subject area. Only columns classified public or internal and tagged to that area are described to the model.
- 3Generate
The model writes SQL from metadata alone. It never sees a row of data.
- 4Gate
The SQL is parsed and checked against policy: no restricted columns, no bulk row listing, read-only account.
- 5Run and record
Executed as a SELECT-only account through the BI tool, published as a chart, logged with tokens, duration and outcome.
Ask, scope, get a chart
Captured from the reference banking build on synthetic data. Click to enlarge.
Numbers from our reference build
Measured on a 66-question golden set over a medallion warehouse, cloud tier. Your figures will differ with your schema and model.
Scoping is the biggest lever: ticking one subject area took the schema offered to the model from 751 columns to 59, and the finance set from 12 of 16 to 16 of 16.
Same gatekeeper, your choice of model
Accuracy and latency are what you buy with model size and hardware. The controls, scoping, audit and repair loop are identical across all three.
Cloud
- Latency
- ~3 s
- Fit
- Fast, interactive, non-restricted data only
On-host CPU
- Latency
- 1 to 12 min
- Fit
- Restricted data, batch questions, nothing leaves the host
On-host GPU
- Latency
- 2 to 7 s
- Fit
- Restricted data, interactive, 13 of 16 finance questions correct
What the model is never allowed to do
See a row of data
Only metadata reaches the prompt. Results go to the user through the BI tool, never back through the model.
Read a restricted column
Classification defaults to unclassified, which is hidden. A new column stays invisible until someone classifies it.
List people
Row-level listing of person-shaped tables is refused at the SQL level, whatever the model proposes.
Write anything
The execution account holds SELECT and nothing else. Read-only settings are not trusted as the boundary; the grant is.
Go unrecorded
Who asked, what was generated, how long it took, what it cost and whether it was refused, in the audit database.
Train on your data
Cloud tier runs under no-training terms. On-host tiers never leave the machine.