Database governance for MCP and AI

Decide, database by database, what Claude, ChatGPT or Cursor may query. With SaturnSQL Enterprise every connection has its own AI access setting, every AI query is tied to a named person, and the audit log shows exactly what ran on each database. The model never sees a password.

ConnectionsAI access
prod-postgres
PostgreSQL · user ai_readonly
Read-only
analytics-replica
MySQL · replica
Read-only
billing
SQL Server · PII
Off
staging
PostgreSQL
Same as people

Most database MCP servers are a process on someone's laptop with a connection string in a config file. The model can reach whatever that string can reach, nothing records what it ran, and the database sees one shared user. LLM governance for data starts at the connection: which databases an LLM may touch, as which database user, with what rights, and with a record of every query.

AI access is set per connectionEnterprise

Each connection has one AI access setting, separate from what people can do in the SaturnSQL editor:

  • Off. AI clients and API keys cannot see or query the connection. People still use it in the editor as usual.
  • Read-only. AI clients can query it, but every call must be a single SELECT, WITH or EXPLAIN statement, even if people are allowed to write.
  • Same as people. AI clients get the same rights as the person they act for. Meant for staging and scratch databases.

Only the connection's owner and company admins can change the setting, and it is enforced on SaturnSQL's servers before a query reaches your database, not by asking the model to behave.

Limit tables and columns in the database itself

A prompt cannot be trusted to stay away from the salaries table, so put the boundary where the model cannot argue with it. Create a database user that can only read the tables or views you choose, add it to SaturnSQL as its own connection, and make that the only connection with AI access. The full-rights connection stays Off for AI, and the model can never see more than that user can. See creating a read-only database user.

Every AI query has a name on it

Teammates connect Claude, ChatGPT or Cursor by signing in with their own SaturnSQL account over OAuth. There is no shared API key and no service account hiding who asked. The AI only sees the connections shared with that person, under their role, and viewers have no SQL access for an AI client to borrow. Remove someone from the workspace and their AI clients stop on the next request, because membership is checked on every call.

An audit log per connectionEnterprise

Every query is recorded, whether it came from the SaturnSQL editor, a schedule, an API key or an AI client. Each entry has the time, the person, the client or named key, the connection, the full SQL, the row count, the duration and any error. Filter to one connection to see everything AI did on that database, and export it as CSV for a compliance review.

The model never holds the credentials

Connection credentials are encrypted with AES-256 on SaturnSQL servers and never sent to the browser or the AI client. Claude sends SQL and gets rows back, capped by row limits. Your database does not need to be open to the internet either: allow the static egress IP 100.49.19.161, tunnel through an SSH bastion, and pin your own CA for TLS.

Checklist

ControlHow SaturnSQL does it
Choose which databases AI can reachAI access set per connection: Off, Read-only or Same as people (Enterprise)
AI cannot change dataRead-only AI access accepts one SELECT, WITH or EXPLAIN per call
Limit tables and columnsA separate connection with a restricted database user, the only one open to AI
Credentials never reach the modelEncrypted with AES-256, kept server-side
Every AI query tied to a personOAuth sign-in per person, no shared key
Full record per connectionAudit log with person, client, full SQL and rows, exportable as CSV (Enterprise)
Only owners change the rulesAI access is editable by the connection owner and admins
No database open to the internetStatic egress IP, SSH bastion, TLS with your own CA

What SaturnSQL does not have

Better to read it here than find it in procurement: there is no column-level masking inside SaturnSQL (use a restricted database user), no SAML single sign-on or SCIM provisioning, no self-hosted option, and no SOC 2 or ISO 27001 report. The full picture is on the security page, and contract terms, including subprocessors, are in the data processing agreement.

Common questions

Which plan includes this? Per-connection AI access and the audit log are part of the Enterprise plan. Everything else on this page, including per-person OAuth sign-in, read-only connections, encrypted credentials and the SSH bastion, comes with Starter and up, the plans that include the MCP connector.

Do I need an MCP gateway as well? A gateway sits in front of many MCP servers and applies one policy to all of them. For database access, SaturnSQL already is that control point: it authenticates each person, applies each connection's AI access setting, and writes the audit log before a query reaches your database. A gateway still makes sense if you also run many unrelated MCP servers.

Can an admin see the exact SQL Claude ran on a connection? Yes. The audit log stores the full statement for every query, with who ran it, which AI client or API key it came through, the row count, duration and any error. Filter it to one connection to review everything AI did on that database.

Does the AI ever see our database password? No. Connection credentials are encrypted with AES-256 and stay on SaturnSQL servers. Claude, ChatGPT or Cursor sign in with the person's SaturnSQL account and only receive query results.

What happens when someone leaves the company? Remove them from the workspace. Membership is checked on every request, so their connected AI clients stop working on their next call, without waiting for a token to expire.

Can I hide specific tables or columns from the AI? Do it in the database, where it cannot be bypassed. Create a database user that can only read the tables or views you choose, add it as its own connection, set that connection to Read-only AI access and turn AI access off on the full one. The model can only ever see what that user can see.

Do you support SAML SSO or have a SOC 2 report? Not today. Sign-in is email and password or Google, with optional TOTP two-factor authentication, and we have not been through a SOC 2 or ISO 27001 audit. If either is a hard requirement, SaturnSQL does not meet it yet.

Part of SaturnSQL Enterprise. For how people get access without sharing passwords, see database access management. Setting up a client? See Claude, ChatGPT, Cursor or Claude Code, or build Claude Dashboards on your database.

Rolling out AI access across a team? Talk to us about Enterprise.