SQLGuard · AI Action Authorization · SQL beachhead
The problem is not only AI mistakes — it is missing proof of what the AI was allowed to do.
band: low · free tip — not authorize
Keep PASS+verify on every mutate. Re-run when adding write tools.
Machine: GET/POST /v1/risk · Policy /require · Cite /ai-sql-authorization