Blog

Connecting AI to your data.

Notes on MCP, database access, and keeping AI tools local to your infrastructure.

Written by the people building Bufflehead. No newsletter gate — read and go.

2026-10-01

Who's asking? Give every agent query a name.

Give an AI agent a scoped read-only Postgres role, then find its session in the database logs. A tested walkthrough with real log lines, and what Bufflehead does and does not do.

2026-09-29

Cheaper tokens ≠ cheaper deployments

Measure AI deployment cost per successful outcome with read-only Postgres SQL. Include retries and failures, check billing coverage, and keep unit cost separate from ROI.

2026-09-25

Why did paid installs drop? Query the rollup, check the coverage.

Check attribution import coverage before explaining an install drop. A read-only Postgres walkthrough for AI analytics, campaign comparisons, and correctly weighted rates.

2026-09-24

Ask before you query: when an AI should clarify revenue

Gross sales, paid orders, or revenue after refunds? A Postgres walkthrough showing when an AI should ask for a business definition before querying through read-only access.

2026-09-23

Your AI ran valid SQL. Did it answer the question?

Five Postgres checks for AI-generated SQL: totals, rankings, date boundaries, duplicate joins, and missing data. Verify the answer, not just whether the query runs.

2026-09-21

Was that the right price—on the order date?

Compare invoice prices with effective-dated catalog data using read-only Postgres SQL. Surface missing periods, overlapping prices, and currency or unit mismatches.

2026-09-20

Read-only SQL is not a data-access policy

Read-only access prevents writes, but does not decide which data an AI may read. Test a scoped Postgres role with allowed and denied queries through Bufflehead.

2026-09-19

Stop pasting your database into the prompt

Give AI useful database context with schema, relevant samples, and focused SQL. A read-only Postgres walkthrough inspired by Matthew Brown’s Claude demo.

2026-09-03

MCP Scoping and Permissions: Why "Three Read-Only Tools" Isn't Actually Read-Only

The tool boundary isn't the security boundary — query construction and credential grants are. Why read-only enforcement belongs at the connector layer, not just the DB layer.

2026-08-29

"The MCP server did it" is a bad line in your audit log

Query-logging and credential-attribution are different problems. Scrubbed views and pgaudit fix the first one; per-engineer credentials fix the second.

2026-08-26

Connecting Claude to MySQL or MariaDB: Three Architectures Compared

Remote MCP on the DB server, local MCP with a direct connection, or local MCP over an SSH tunnel — the tradeoffs that actually matter for stability, security, and maintenance.