After an AI Agent Nearly Leaked Another Tenant's Revenue, Dev Open-Sources Canonic MCP Server

canonic-app · reddit · 2026-09-06

A developer found their multi-tenant analytics LLM agent generated technically valid SQL that joined across tenant boundaries — no prompt injection needed. Semantic layers like dbt describe metrics but don't enforce mandatory filters or tenant scoping.

They built canonic, an open-source context layer between agent and warehouse that compiles business rules (mandatory filters, required dimensions, tenant/role scoping) directly into every query, and returns answers with a trust score explaining why they should be believed. Ships as an MCP server for Claude Code, Cursor and others; ingests dbt/LookML or raw schemas.

Original post →

More from coding & agent

coding & agent channel →