AddThisFeature

Natural Language Database Query

Answer plain-language data questions through a read-only, reviewable query path.

involved Developer Experience

What it adds

An internal query surface that translates a question into a restricted read-only query over an approved schema subset.

What your agent is told to do

5
  1. 1

    Define an approved semantic layer — the specific tables, columns, and joins this feature may touch — and expose only that to the model. Do not hand it the full schema and rely on instructions to keep it away from sensitive tables.

  2. 2

    Execute through a connection that is read-only at the database level, with a row limit, a time limit, and a separate credential from the application's own. Permissions in the prompt are not permissions.

  3. 3

    Parse and validate the generated query before running it: reject anything that writes, alters, calls a function outside the approved set, or touches a table outside the semantic layer. Rejection must be the default for anything unrecognised.

  4. 4

    Show the query and the tables it reads alongside the results for any user permitted to see them, and log every generated query with the requesting user and the question that produced it.

  5. 5

    Restrict access to this feature to operators and support staff by the app's own permission system. Customer-facing data questions belong to Natural Language Report Builder and Natural Language Filters, which run against defined metrics rather than raw tables.

Edge cases it handles

8
  • Only the approved schema subset may be reachable. A query that joins its way to a table outside the semantic layer must be rejected by the validator regardless of how reasonable it looks.
  • Read-only enforcement must live in the database credential and the validator, not in the instruction to the model. A single successful write from a generated query is unrecoverable.
  • Every generated query must pass validation before execution, and an unparseable or partially truncated query must be discarded rather than repaired by guesswork.
  • Content stored in the database can contain text written to steer a model. Treat all query results and any row content included in a follow-up as untrusted data, never as instructions.
  • Showing the query and its source tables is what makes a wrong answer detectable. A bare number with no visible query will be quoted in a meeting and never checked.
  • An unbounded query can lock tables or exhaust a connection pool. Enforce row and execution-time limits and run against a replica where one exists.
  • Results may contain personal data. Decide what may be sent back to the model for summarisation, redact what must not leave, and never send raw customer records simply to phrase an answer.
  • When the model is unavailable, the feature should say so plainly. Do not fall back to executing a stored guess or a previous session's query.

Definition of done

9
  • The model can reference only the approved semantic layer, and queries touching anything else are rejected.
  • Execution runs on a read-only credential with enforced row and time limits.
  • Every generated query is validated before execution and rejected by default when unrecognised.
  • The executed query and its source tables are shown to permitted users, and every query is logged with its requester.
  • Database content is treated as untrusted data and cannot redirect the model's behaviour.
  • Access is gated by the app's permission system to operator-level roles.
  • Model unavailability produces a clear message rather than any fallback execution.
  • The feature matches the existing design system.
  • No existing functionality is broken.

Related features

How it works

  1. 1

    Copy the link

    Grab the Markdown instruction URL for this feature.

  2. 2

    Give it to your AI

    Paste it into Claude Code, Cursor, v0, Lovable — whatever you build with.

  3. 3

    It inspects, then implements

    Your agent reads your existing app first, then adds the feature to fit it.

Works with your stack

These instructions are written to adapt. They tell the agent to detect your framework, match your existing design system, and reuse what you already have — rather than assuming a particular stack.

Need it tighter than that? Customize the feature and tell it exactly what you're running.