Natural Language Database Query
Answer plain-language data questions through a read-only, reviewable query path.
What it adds
An internal query surface that translates a question into a restricted read-only query over an approved schema subset.
What your agent is told to do
5
What your agent is told to do
5-
1
Define an approved semantic layer — the specific tables, columns, and joins this feature may touch — and expose only that to the model. Do not hand it the full schema and rely on instructions to keep it away from sensitive tables.
-
2
Execute through a connection that is read-only at the database level, with a row limit, a time limit, and a separate credential from the application's own. Permissions in the prompt are not permissions.
-
3
Parse and validate the generated query before running it: reject anything that writes, alters, calls a function outside the approved set, or touches a table outside the semantic layer. Rejection must be the default for anything unrecognised.
-
4
Show the query and the tables it reads alongside the results for any user permitted to see them, and log every generated query with the requesting user and the question that produced it.
-
5
Restrict access to this feature to operators and support staff by the app's own permission system. Customer-facing data questions belong to Natural Language Report Builder and Natural Language Filters, which run against defined metrics rather than raw tables.
Edge cases it handles
8
Edge cases it handles
8- Only the approved schema subset may be reachable. A query that joins its way to a table outside the semantic layer must be rejected by the validator regardless of how reasonable it looks.
- Read-only enforcement must live in the database credential and the validator, not in the instruction to the model. A single successful write from a generated query is unrecoverable.
- Every generated query must pass validation before execution, and an unparseable or partially truncated query must be discarded rather than repaired by guesswork.
- Content stored in the database can contain text written to steer a model. Treat all query results and any row content included in a follow-up as untrusted data, never as instructions.
- Showing the query and its source tables is what makes a wrong answer detectable. A bare number with no visible query will be quoted in a meeting and never checked.
- An unbounded query can lock tables or exhaust a connection pool. Enforce row and execution-time limits and run against a replica where one exists.
- Results may contain personal data. Decide what may be sent back to the model for summarisation, redact what must not leave, and never send raw customer records simply to phrase an answer.
- When the model is unavailable, the feature should say so plainly. Do not fall back to executing a stored guess or a previous session's query.
Definition of done
9
Definition of done
9- The model can reference only the approved semantic layer, and queries touching anything else are rejected.
- Execution runs on a read-only credential with enforced row and time limits.
- Every generated query is validated before execution and rejected by default when unrecognised.
- The executed query and its source tables are shown to permitted users, and every query is logged with its requester.
- Database content is treated as untrusted data and cannot redirect the model's behaviour.
- Access is gated by the app's permission system to operator-level roles.
- Model unavailability produces a clear message rather than any fallback execution.
- The feature matches the existing design system.
- No existing functionality is broken.
Related features
Multi-Model Routing
Multi-Model Routing
Send each AI request to the right model using rules you can read and test.
What it does
A deterministic routing layer that picks a model per request from task type, context size, latency budget, and data sensitivity.
How it works
- 1 Express routing as explicit, ordered rules over inputs the app can measure: task type, estimated context size, latency budget, and the sensitivity classification of the data involved. A rule set that can be read line by line can be reviewed and tested.
- 2 Make routing deterministic. The same inputs must always produce the same route, so a bad output can be reproduced and a rule change can be evaluated. Randomised or load-based selection turns every incident into guesswork.
- 3 Classify data before routing and refuse to route restricted content to any destination not approved for it. This check is a hard block, not a preference, and it must run before the request is assembled.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/multi-model-routing
AI Cost Budgets
AI Cost Budgets
Cap what AI features are allowed to spend before the bill arrives.
What it does
Monetary spending limits on AI work, scoped by workspace, feature, and time period, enforced before a run starts.
How it works
- 1 Find every place the app calls a model and route all of them through one accounting point that records estimated and actual spend against a scope. A budget that only covers the chat feature is not a budget.
- 2 Estimate the cost of a run from the size of its input before dispatching it, and refuse anything that would exceed the remaining budget on its own.
- 3 Reserve the estimate against the budget when the run starts, then reconcile to the real usage figures when it finishes, releasing whatever was over-reserved.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/ai-cost-budgets
Model Selection
Model Selection
Let each AI task run on the model that suits its quality, speed, and cost needs.
What it does
A per-task model choice, drawn from the models the app already has configured, with capability filtering and safe defaults.
How it works
- 1 Enumerate the models the app already has access to and record what each one can actually do: context capacity, whether it can return the structured output the task requires, whether it supports the tools the task calls, and its relative cost and speed.
- 2 Offer only the models that satisfy the task's requirements. A task that needs structured output must not list a model that cannot reliably produce it, because the failure appears later as malformed responses rather than as an unavailable option.
- 3 Store the choice against the specific task, not as one global setting. A single default forces a summarisation task and a classification task onto the same tier when they have opposite needs.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/model-selection
How it works
-
1
Copy the link
Grab the Markdown instruction URL for this feature.
-
2
Give it to your AI
Paste it into Claude Code, Cursor, v0, Lovable — whatever you build with.
-
3
It inspects, then implements
Your agent reads your existing app first, then adds the feature to fit it.
Works with your stack
These instructions are written to adapt. They tell the agent to detect your framework, match your existing design system, and reuse what you already have — rather than assuming a particular stack.
Need it tighter than that? Customize the feature and tell it exactly what you're running.