Security checklist before wiring AI coding agents to a production database
idontlikepeople26 · reddit · 2026-10-01
An engineer who has to sign off on connecting Claude and Cursor to the data warehouse shares a pre-approval checklist:
- Dedicated read-only role with no access to raw PII schemas
- Row limits on anything the agent can run
- Query logs a human can actually read afterwards
- One credential per tool so a single leak can be contained
- Where the data goes after a query — local server or a hosted one that sees the rows
- Whether anything gets stored along the way
He stresses the last two are where vendors give vague answers: "we don't train on your data" is not the same as "we don't keep it," a distinction that has to be explained to security teams. He asks what's missing from the list and what unexpected pushback others hit.
More from coding & agent
- Coding agents waste 10x tokens reading files: 955-job benchmark of a code-graph MCP server — Classeve · 2026-10-01
- Open-Source Runtime Security Layer Keeps Credentials Out of AI Agents — Technical-Spread-368 · 2026-10-01
- Atelico CEO: AI Makes Games Worse—On-Device Small Models Can Fix It — bigdata · 2026-10-01
- Codelab: Build an Apache Iceberg Lakehouse on GCP without external catalogs — jggomezt · 2026-10-01
- Dev shares agent prompt to mine Cloudflare's weekly launches for competitive leverage — threepointone · 2026-10-01
- Google Cloud to release 31 free hands-on episodes on AI agent security this October — dr_cintas · 2026-10-01