After an AI Agent Nearly Leaked Another Tenant's Revenue, Dev Open-Sources Canonic MCP Server
canonic-app · reddit · 2026-09-06
A developer found their multi-tenant analytics LLM agent generated technically valid SQL that joined across tenant boundaries — no prompt injection needed. Semantic layers like dbt describe metrics but don't enforce mandatory filters or tenant scoping.
They built canonic, an open-source context layer between agent and warehouse that compiles business rules (mandatory filters, required dimensions, tenant/role scoping) directly into every query, and returns answers with a trust score explaining why they should be believed. Ships as an MCP server for Claude Code, Cursor and others; ingests dbt/LookML or raw schemas.
More from coding & agent
- Rork claims App Store publishing is now 2.5x to 4x faster — rudrank · 2026-09-07
- Hands-on test: AI ops agent Ghost diagnoses and fixes three simultaneous service failures — BLUECOW009 · 2026-09-07
- Dev runs a live show produced entirely by an agentic AI research team built on a wiki — SurvivedDravoswater · 2026-09-07
- Open-source Codex Skill turns one sentence into a holographic 3D card with Blender and Three.js — Promptmethus · 2026-09-07
- Jim Koppel: the vibe coder's way to understand code is running everything; the agentic engineer reads it — jimmykoppel · 2026-09-07
- OpenAI reportedly testing ChatGPT feature that mimics your writing style from emails and docs — VraserX · 2026-09-07