Section 7: Locking Down Database Access for AI
- The risks when AI runs SQL: changed data, heavy queries that slow systems and data leaks
- Create a read-only role and a dedicated schema or views that the AI can see
- Set statement_timeout, cap the number of rows and point the agent at a read replica
- Lab: prove the agent cannot delete or change data, even when told to in a prompt
Section 8: Lab: SQL Guardrails Before Execution
- Parse SQL with sqlglot to confirm it is a SELECT statement only
- Allowlist tables and columns and add a LIMIT automatically
- Mask personal data in results and log every question and SQL statement
- Deal with prompt injection hidden in data or in user questions
Section 9: Evaluation: Measuring Data Agent Accuracy
- Build a test question set with correct answers from real business team questions
- Execution accuracy: compare query results rather than the SQL text
- Classify errors, such as wrong table, wrong filter or wrong metric definition
- Lab: build an evaluation notebook and report scores before and after improvements
Section 10: Lab: Database Access through MCP
- What the Model Context Protocol (MCP) is and how it gives AI assistants access to data
- Choose a database MCP server, such as MCP Toolbox for Databases, and confirm it runs read-only
- Connect PostgreSQL to Claude Desktop or another MCP client using a read-only role
- Write your own MCP tool that runs metrics from the semantic layer instead of free-form SQL
Section 11: Delivering Answers Users Can Trust
- Answer with numbers, a chart, the SQL used and the assumptions in plain Thai
- Tell users when a question is outside the data's scope instead of guessing
- Collect feedback on right and wrong answers to grow the query library
- Lab: build a simple data chat page on Colab for classmates to try
Section 12: Workshop: Capstone Data Agent for a Business Team
- Pick a scenario, such as sales, finance or customer service, and set the scope of questions
- Design the full set of context, semantic layer, permissions and guardrails
- Measure with the test question set and fix what is still wrong
- Present the work, review it together and wrap up with a checklist before opening it to real users