One dataset per endpoint
The endpoint always runs the same published query. An agent cannot send its own SQL and therefore cannot go searching through your warehouse.
AI agents
AI agents for business are AI systems that carry out tasks on their own, such as retrieving data, drafting a report or triggering an action in another system. How secure they are depends mainly on the data they can access. ENABLE doesn't run agents itself, but provides the controlled data layer: published, read-only query endpoints with an API key, so an agent gets exactly one scoped dataset.
Saved query · revenue-by-region · version 3
{
"query": "revenue-by-region",
"version": 3,
"rows": [
{ "region": "South", "revenue_2026": 1421300 },
{ "region": "North", "revenue_2026": 1284900 },
…
]
}AI agents for business are AI systems that don't just answer, but take steps themselves: looking up information, calling a tool, drawing a conclusion and sometimes carrying out an action. An agent that prepares the stock report every Monday, for example, needs to be able to retrieve stock and sales figures.
That is exactly where the biggest risk lies. An agent with broad access to your database or systems can see and do more than necessary, and afterwards it is hard to trace why it did something. Working responsibly with AI agents therefore starts with limited, verifiable access to data.
ENABLE does not run AI agents itself and is not an agent platform. What ENABLE does do: publish a query from your data warehouse as a secured REST endpoint. An agent or automation you build elsewhere then gets exactly that one read-only dataset, with its own API key, an OpenAPI specification and rate limits.
Key points
The endpoint always runs the same published query. An agent cannot send its own SQL and therefore cannot go searching through your warehouse.
Every call runs in a read-only transaction. Through ENABLE, an agent cannot change, add or delete anything.
Each endpoint has its own key in the X-API-Key header. If you switch off the publication, the endpoint stops working.
ENABLE describes your published endpoints in an OpenAPI specification. Many agent and automation tools can import such a specification as a tool description.
You decide which parameters an endpoint accepts, such as a period or branch. An agent cannot add other filters.
The number of calls per endpoint and caller is capped, as is the number of rows per response. That limits the damage if an agent gets stuck in a loop.
An endpoint serves the published version of the query. Changes only go live when a customer admin republishes, and that is recorded in the activity log.
An AI agent combines a language model with tools, such as an API, a database or a mailbox, and lets the model decide for itself what the next step is. Businesses use agents or "digital workers" to prepare reports, sort incoming requests or enrich data, for example. This is also known as agentic AI.
The difference from classic workflow automation is that an agent doesn't follow a fixed sequence of steps but decides for itself. That makes it flexible, but also less predictable.
| Chatbot | Workflow automation | AI agent | |
|---|---|---|---|
| What it does | Answers questions | Carries out fixed steps | Chooses its own steps and tools |
| Predictable | Fairly | Yes | Less so |
| Access to systems | Usually none | Configured per step | Through the tools you give it |
| Typical risk | Incorrect answer | Error in the rule | Overly broad access, unexpected actions |
Most problems with agents arise not from the model, but from what the model is allowed to do.
You reduce most risks by giving the agent less: only the data it needs, read-only and through a channel you can shut off. Take the fictional Acme Groothandel. An automation that drafts a stock report every Monday calls one endpoint listing items below their minimum level: item, location, stock and minimum. Purchase prices and customer details are not in that query, so the agent can't see them either.
| Agent with database access | Agent via the ENABLE Data API | |
|---|---|---|
| What the agent can read | Everything the database account can | Only the result of one published query |
| Who decides the query | The agent | A customer admin, when publishing |
| Writing | Depends on the permissions | Not possible, read-only |
| Shutting off | Change the password | Switch off the publication |
| Documentation | Describe it yourself | OpenAPI specification |
With AI automation, the rule is: start small and keep a human in the loop until you know how the agent behaves. You build, host and monitor the agent itself in the tool of your choice; ENABLE supplies the data.
In ENABLE
In the SQL Explorer, write a query, with AI assistance if you like, containing only the columns the agent needs.
Specify which values the agent may pass, for example a period or branch.
A customer admin publishes the query as a REST endpoint. You get an API key and the OpenAPI specification.
Set up the endpoint as a tool in your agent or automation environment and store the API key there as a secret.
Rate limits cap usage. If something doesn't work as intended, you switch off the publication.
FAQ
AI agents are AI systems that independently take steps to complete a task, such as retrieving data, drafting a report or forwarding a request. They combine a language model with tools such as APIs and databases.
No. ENABLE does not run agents itself and is not an agent platform. ENABLE can, however, publish a query from your data warehouse as a secured, read-only REST endpoint that an agent you build elsewhere can use.
Give the agent only the data it needs, read-only and through a channel you can shut off. With the ENABLE Data API, an agent gets the result of one published query, with its own API key and rate limits, instead of a database password.
No. Published endpoints run in a read-only transaction and only execute the fixed, published query. An agent cannot send its own SQL.
Workflow automation follows a fixed sequence of steps that you set up in advance. An AI agent decides for itself which step and which tool to use. That makes an agent more flexible, but also less predictable.
Any tool that can send an HTTPS request with a header. The endpoint expects the API key in the X-API-Key header and returns JSON. Tools that support OpenAPI can use the specification as a description of the endpoint.
In an online demo we show you the portal: dashboards per role, row-level security, plain-language questions and how we set it up and manage it for you.