Agent data governance

    Give AI agents company data, and log every call they make

    Each agent gets its own role, token and daily call limit. It reads certified metrics, sees only the rows its role allows, and every call it makes lands in a named audit trail.

    Most agents reach company data through a shared key

    To give an agent data, teams paste a warehouse credential into a config file or connect it as an admin. The agent then sees everything, nobody can say what it queried, and its answers use whichever table it finds first.

    What changes for each agent

    • Shared credentials

      A role per agent

      The role sets what the agent can read, the token identifies it, and the daily limit caps its calls.

    • Access to everything

      Schema, column and row rules

      Access control sets the schemas, columns and personal data an agent can read, and row scoping limits it to the rows its owner can see.

    • Queries nobody can see

      A named audit trail

      Rig logs every call an agent makes under the agent’s name.

    • Whichever table comes first

      Certified metrics first

      The agent looks up certified metrics and table descriptions, writes the query and tests it before it runs.

    • Changes nobody checks

      Approval before changes

      Changes to source systems, such as a CRM update, wait for a person to approve them.

    • Rules for each tool

      One set of rules

      The same permissions apply in Rig, Claude, Cursor and every other tool connected through Rig’s MCP access.

    How the work runs

    1. Agree the job

      Agree what the agent does and which data it needs, with the business owner and the data team.

    2. Set the role

      Set the agent’s schemas, columns, rows and daily limit, and which changes need approval.

    3. Give it context

      Point the agent at certified metrics, table descriptions and your usage rules.

    4. Review the trail

      Read the audit trail, test results against the task, and adjust the role as the agent’s job changes.

    Where to start

    Common questions

    Which agents does this cover?

    It covers agents built in Rig, and agents in Claude, Claude Code, Cursor, Codex or ChatGPT that connect through Rig’s MCP access.

    Can an agent change data in our systems?

    Yes, but only through the actions you allow, and a person approves each change first.

    How do we keep agent costs under control?

    Each agent has a daily call limit, and the audit trail shows what it used.

    Can two agents see different data?

    Yes. Each agent has its own role, so a payments agent and a sales agent read different schemas, columns and rows.

    What does the audit trail show?

    It shows every call each agent makes, with the agent’s name, the query and the result, so the data team can review the work.

    SOC 2 Type 2EU and US hostingRole-based accessYour warehouse or ours

    Talk to Rig

    What work do you want to improve?

    Tell us where your team spends time, loses money or needs better information.
    In a 30-minute call, we’ll discuss the data and systems work that could help.

    Discuss agent data accessUse the platform with your team, or add our engineers.