Destructive operation guardrails
DROP, DELETE, TRUNCATE, and bulk writes against protected sources are blocked or routed for approval.
Analysts hand agents database access, notebooks, and warehouse credentials to move faster. Knostic makes sure the agent reads what it should, never drops what it should not, and never carries a credential or a PII row out the door.
An agent asked to clean up a table will clean up the wrong one. An agent with a connection string will paste it into a prompt. Knostic checks each action against your data policy before it runs, and catches sensitive values before they leave.
Asked to tidy stale orders data, the agent drops the live orders table. 'Command completed.' Then checkout throws 500s and errors climb.
Kirin recognises the table-deletion rule, denies the command before it executes, and alerts the data owner with the exact query.
Analysts connect notebooks, assistants, and desktop agents to the warehouse on their own. Nobody has the list.
Every AI tool touching data is discovered and attributed to a user and team, with usage trends over time.
Each tool has its own idea of what an agent may read, write, or delete. Policy is enforced differently in each.
One policy for read, write, and destructive operations across every agent, with drift flagged.
DROP, DELETE, TRUNCATE, and bulk writes against protected sources are blocked or routed for approval.
Connection strings, keys, and personal data in prompts and outputs are caught before they leave the agent.
See which user, agent, and tool ran what against which source.
Allow analysts' agents to read curated schemas while keeping raw PII and finance tables off-limits.
Data owners are notified when an agent attempts a blocked action on their source.
Every agent action against data is logged for governance review.
It sits inside the agent. Kirin evaluates the tool call, including the SQL or command, before the agent executes it. No proxy in the data path.
Yes. Policies distinguish read, write, and destructive operations and can be scoped to specific sources or schemas.
Kirin covers coding agents such as Cursor and Claude Code and non-coding agents such as Claude Cowork, which is where most analyst workflows now run.
Kirin's secret and sensitive-data detection inspects prompts, retrieved context, and outputs in real time, in Monitor or Enforce mode.