Notes on MCP, database access, and keeping AI tools local to your infrastructure.
Written by the people building Bufflehead. No newsletter gate — read and go.
Give an AI agent a scoped read-only Postgres role, then find its session in the database logs. A tested walkthrough with real log lines, and what Bufflehead does and does not do.
Measure AI deployment cost per successful outcome with read-only Postgres SQL. Include retries and failures, check billing coverage, and keep unit cost separate from ROI.
Check attribution import coverage before explaining an install drop. A read-only Postgres walkthrough for AI analytics, campaign comparisons, and correctly weighted rates.
Gross sales, paid orders, or revenue after refunds? A Postgres walkthrough showing when an AI should ask for a business definition before querying through read-only access.
Five Postgres checks for AI-generated SQL: totals, rankings, date boundaries, duplicate joins, and missing data. Verify the answer, not just whether the query runs.
Compare invoice prices with effective-dated catalog data using read-only Postgres SQL. Surface missing periods, overlapping prices, and currency or unit mismatches.
Read-only access prevents writes, but does not decide which data an AI may read. Test a scoped Postgres role with allowed and denied queries through Bufflehead.
Give AI useful database context with schema, relevant samples, and focused SQL. A read-only Postgres walkthrough inspired by Matthew Brown’s Claude demo.
The tool boundary isn't the security boundary — query construction and credential grants are. Why read-only enforcement belongs at the connector layer, not just the DB layer.
Query-logging and credential-attribution are different problems. Scrubbed views and pgaudit fix the first one; per-engineer credentials fix the second.
Remote MCP on the DB server, local MCP with a direct connection, or local MCP over an SSH tunnel — the tradeoffs that actually matter for stability, security, and maintenance.