The panic → approval path
SQLGuard is the approval firewall between the agent and production.
Unique question: was this exact action authorized before it happened?
Decide returns ALLOW, DENY, or REQUIRE_APPROVAL — bound to request, policy, scope, and expiry.
Probe is free tip only. Session is not the wealth path.
What AUTHORIZED means
- Policy checked the exact SQL under scope and TTL
- Signature verifies against the live issuer pubkey
- Invoice or Exact settle funded the permission path
What it does not mean
- That the write is safe for your business or schema
- That we operate your production database
- That lint, OAuth, or DB roles authorized the statement
1. POST /v1/challenge → DENY + deny_id
2. Prove at $0: POST /v1/challenge/try · or Graduate Exact Pilot $100 → cert → verify
3. Companies: Gateway invoice $299/mo → hello@sqlguard.io