Who is asking?
Bind the request to a human or service identity. No identity means no schema and no answer.
A practical framework for deciding when an enterprise data agent may answer, when it must defer, and what evidence an organization should retain.
Explore the controlsUse the test setBind the request to a human or service identity. No identity means no schema and no answer.
Apply policy before retrieval and again against every object and action in the proposed query.
Resolve material terms to owned, versioned definitions—including grain, period, currency and exclusions.
Parse, constrain and compile the query, then rely on a least-privileged source principal as defense in depth.
Choose verification strength based on decision impact. An unavailable verifier is never a pass.
Refuse unsupported, unauthorized or unsafe requests without leaking restricted objects or inventing evidence.
Retain the SQL, objects, policy result, semantic version, data state and verification outcome.
Test drift, revocation, monitoring, incident response, retention and an independently operable kill switch.
The authorized data and approved meaning support the question. Record the evidence and result.
The data exists, but a business term is ambiguous. Apply a certified definition or ask.
The request is unsupported, unauthorized or unsafe. Decline without guessing or disclosing.
The framework maps selected controls to Mnemiq, an open-source text-to-SQL engine developed by Agentic Fabriq. Each mapped claim names public evidence and separates implemented product behavior from deployment responsibility.
How the projects relate Read the evidence map Read the executive briefingProject status: Enterprise Data Agent Governance is an independently maintained open-source project. Its relationship to the upstream Mnemiq foundation is documented on the Built on Mnemiq page.