Urgent.News

What's breaking now, across thousands of outlets.

AI

An Analytics Agent's Permissions Should Survive a Bad Prompt

An analytics agent receives a hostile instruction: return every customer's unmasked payment identifier. The key question is what the system permits that agent to read—even if the model decides to follow the instruction. That is the boundary I am exploring in MerchantLens , a merchant analytics lakehouse built with Databricks, Delta tables and Unity Catalog. The demo uses synthetic payments data.…

When an analytics agent receives an improper command, such as requesting every customer's unmasked payment identifier, it raises critical questions about the system's permissions. The MerchantLens, a merchant analytics lakehouse built using Databricks, Delta tables, and Unity Catalog, serves as a demonstration of this issue. The tool operates within Bronze, Silver, and Gold layers, with an agent querying live catalog metadata and utilizing tools for metrics or SQL operations.

The agent operates under its own service principal, with Unity Catalog applying column masks and row filters based on that principal's permissions before delivering query results. The entitlement decision rests with the query engine, separate from reliability controls.

The repository highlights several layers contributing to controlled agent behavior: certified metrics to maintain consistent definitions and grain, application checks to constrain SQL, schemas, rows, and tool steps, and Unity Catalog policies to enforce identity-based row and column access. Audit records document tool activity independently of the query's output.

While these measures help secure the application, the overall protection depends on correctly configured identities, grants, masks, and filters, as well as every query using the intended principal.

A practical lesson from the documentation emphasizes the importance of testing protected tables using the actual identity, rather than only checking membership expressions. This ensures a thorough understanding of what the mask does, as relying solely on membership expressions can provide an inaccurate picture. The documentation also emphasizes the need to review ambient grants on new service principals, as granting automatic access does not equate to a deny-by-default setup.

Additionally, metric definitions should be explicit and shared across dashboards and agents to maintain consistency, particularly in cases where the definition of a metric can impact results, such as in chargeback incidents.

Before granting an agent access to a warehouse tool, it is crucial to consider several factors, including the principal executing queries, potential retrieval of restricted columns through other tables or grants, testing of results under that principal, logging of tool calls inaccessible to the agent, and explicit metric definitions shared among stakeholders.

Ultimately, the question remains: where does an analytics agent's access control execute—within the prompt, the application, or the database? Understanding the architecture and platform findings can help answer this critical question.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in AI

I Built a Village of Six Agents You Can Actually Inspect

An agent claims a task. Another agent needs the same resources. A third is resting. Who gets the job, and can you explain the decision afterward?

  • Six agents work together in inspectable simulation game Settlement.
  • Agents assigned tasks, coordinate resources, and reassess as needed.
  • Inspector feature provides visibility into jobs, spending limits, and agent memories.

Opus 5.5 loves to tell you ‘this matters’ (and other AI writing tells)

Opus 5.5’s biggest tell is the word “dependable,” which pops up 23 times more often than in human samples.

  • "Dependable" appears 23 times more often in Claude Opus 5.5's writing than in humans
  • "This matters" occurs 116 times more frequently in Opus 5.5 than in human writing
  • Astra model emphasizes "another dimension" and uses "may provide" or "can provide" hedging

I gave my coding agent a sense of taste. It picks restaurants from my music.

My coding agent can refactor a thousand lines without breaking a sweat, but ask it "where should I take a date Friday night" and it's useless. It knows my code. It knows nothing about my taste.

  • Qloo coding agent gains taste sense
  • Qloo Taste API connects 250M cultural entities
  • Agent recommends restaurants based on music preferences

More from Thursday 1 October →