A model writes plausible SQL. Plausible is not the same as permitted. This release puts the platform's row-security resolver in the path of every query a model writes, and bounds how long an agent may keep trying.
Row security on model SQL
- Strict resolution The resolver validates the row-level policies of the queried table and of its secured parents. A query that references a secured parent without joining it raises an exception rather than leaking rows.
- Transformed, not injected Predicates are applied by transforming the query model rather than by splicing text, and foreign-key relationships are validated on the way.
Bounded agents
- Caps per agent The global default of fifteen iterations gives way to seven for the SQL, coding and dictionary agents, five for knowledge and document, and eight for the orchestrator.
- Approval without code A tool defined in the dictionary can demand approval through a flag, and dictionary writes are gated for every user by default.
The approval gate decides whether an action runs. These guardrails decide what the model is allowed to ask for in the first place.