Per-key scope
Credential 綁定到實際 database 與允許的 MCP tools。
Credential 綁定到實際 database 與允許的 MCP tools。
Table allowlist 與 query policy 不受模型指令影響。
Rate limit、concurrency、revocation 與 audit 都在 prompt 之外執行。
Prompt 不是 authorization system。hs-sql-agent 會先檢查 authenticated key、database binding、allowed tools、table boundary 與 runtime security policy,之後 SQL 才可能進入 execution。
MCP key 可以只綁定 client 真正需要的 database 與 tools。Built-in tool 與已發布的 Custom Tool 在 invocation 前都會經過 key configuration 檢查。
Query 與 DML execution 會留下 tool、operation、timing、returned / affected rows、approval state 與 compiler-derived facts 等 audit context。模型互動結束後,治理仍然可以被檢查。