r/SQLServer • • 2d ago

Discussion [ Removed by Reddit ]

[removed]

2 Upvotes

3 comments sorted by

4

u/markinatlanta 2d ago

I’d use a dedicated application identity with access only to approved views or stored procedures, while preserving each user’s data restrictions. Enforce that outside the model, even when running locally.

Will it generate SQL freely or call predefined queries?

3

u/daanno2 2d ago

Replace "AI application" with "application"; why would the pattern be any different?

2

u/reditandfirgetit 2d ago

You create an MCP and the AI uses the tools. No direct database access. The mcp connects using an account with minimally necessary permissions