Connector rules (plain text). These are the rules the worked example follows. Access - The connection uses an account with read permission only. The account cannot write, whatever the script allows. - Two commands are offered to the assistant: describe (list tables, columns, declared keys) and query. - query accepts one statement per call. It must start with SELECT or WITH. Anything else is refused and logged. Limits - Every result is capped at 200 rows. A truncated result is marked as truncated. - Models are built in a scratch copy of the data. Nothing is created in the source database. Credentials - The credential is held by the script, in the environment on my machine. - The assistant calls the script. It does not see the credential, so the credential is not in prompts, files or logs. Logging - Every call is logged with its purpose, its SQL text, the number of rows returned and the outcome. - In the worked example: 40 statements logged, 3 refused, 1 truncated by the cap. Review - A person reviews every proposal. A failing check stays failed until the cause is fixed or the owner of the data signs off. Limits of this description - In the worked example the source database is a local file and the connector is a demonstration of these rules. It is not a security review.