D-CAT Group ↗ Contact ENTRDEESAZ
Start a 4-week pilot

Architecture

Your data never leaves. The model never enters.

AgenticObjects runs in your environment. The only components that touch data are read-only gateways. The model cannot reach the database, the authorization layer or query execution — and the model selected for a run cannot change while the run is going.

The boundary

Where the AI can and cannot reach

Where the model sits relative to your data Your environment contains the app and console, the deterministic harness, two read-only gateways and your data warehouse. The language model sits outside that boundary and receives text only: no credentials, no data path, no authorization decisions. YOUR ENVIRONMENT App & Console business users and administrators Harness: deterministic services QueryBuilder · calculation · authorization spend control · FinalGuard · object repository · audit log SQL gateway read-only SSAS gateway read-only Your data warehouse and cubes — in place, never copied OUTSIDE THE LINE Language model receives text, returns narration. No credentials. No data path. No authorization decisions.
Harness, gateways and repository run on your server. The model is outside the line: it receives text and returns narration.

Where the AI cannot reach

query building · query execution · number verification · authority decisions · spend control · publication decisions

What the AI does

understand the question · write the sentence

The control chain

Six controlled stages between your data and the sentence. The model is in one of them.

The trust model does not rely on prompting. It relies on a deterministic control chain — and on recording what that chain refused.

01Semantic Contract

One authoritative, versioned definition per metric. If a question does not match a definition, the system says so instead of guessing. The model is not consulted about what a metric means.

02QueryBuilder

Deterministic query construction from the contract. The model never writes the query that runs.

03Read-only gateway

The only component that touches your data. Write and multi-statement forms are rejected at the gateway grammar before they reach the database. No write path exists by design.

04Narration
the model, here only

Reads the sealed results and writes the sentence — nothing else. Every number it uses must declare its address. It cannot divide; it asks the engine for the ratio.

05FinalGuard

A rule-based comparator, not an AI. A number without a source, inconsistent with the query, or written before a query ran is rejected. There is no setting, no permission and no button to disable it. Comparison takes about two milliseconds — demo measurement.

06Publication gates

Eight deterministic checks decide whether a candidate becomes a record: structure, authority freeze, evidence, trust stamp, claim check, novelty, deduplication, cardinality. The AI proposes; the engine decides.

Four architectural facts

The parts that do not move

On-premise

The app, runtime, semantic layer and object repository run on your server. Analysis goes to the data; the data does not go anywhere.

Read-only

Two gateways touch data and both are read-only. Write and multi-statement forms are rejected at the gateway grammar before they reach the database.

Model isolation

The model sees text only. Database credentials, the direct data path and authorization decisions are outside its reach.

One model per run

Once a run starts, the selected model does not change: not for a slow or failing provider, and not because a first answer looked weak. No automatic fallback, no quality-triggered escalation. Bring your approved model, and it is the one on the record when someone asks six months from now.

Under the hood

Where exactly is the AI involved? Your technical team will ask.

ComponentResponsibility
Application core PHPConsole for administrators, App for business users, routing and authorization, import/export
Agent runtime PythonThe agent loop: plan, call tools, evaluate; every step an idempotent event
QueryBuilderBuilds the query deterministically from the Semantic Contract — never touches the model
SQL gateway JavaThe only hand that touches relational data; read-only statement guard
SSAS gateway .NETCube access via DAX/MDX, read-only
Storage and queueRelational system-of-record for the product; a queue for runs
Semantic Contract .axrOne versioned definition per metric; authored in Axoria Data Studio, imported here
Resume-first

If a run is interrupted, it resumes from the first incomplete step. A completed step never runs again — no duplicate cost, no duplicate finding.

Schedules are standard recurrence rules with a timezone per job, and the scheduler scans every minute, so an hourly rhythm fires on time. Hourly or daily is what we recommend, because your warehouse is unlikely to refresh faster. A run that was missed catches up at most once, and only if it is still recent: a nightly report firing thirty hours late would describe today, not the night it belonged to.

Governance

Authority never shifts. The budget freezes. Everything is on the record.

Authority

  • Four roles with a clear hierarchy: viewer, editor, admin, company admin.
  • Sensitive actions come from named permissions, not roles: seeing the executed SQL, running experiments, raising a budget.
  • Row-level security: the administrator defines the rule; the system generates the filter clause. If the identity cannot be resolved, it stops.
  • Policy as code: permissions live in a single source from which guard, middleware and tests are generated.
  • Even learning is human-gated: a single approval queue.

Budget

  • Every run has a ceiling — steps, seconds, cost — and it freezes when the run starts.
  • An agent can only narrow its limits, never widen them. A channel can change the budget, never the authority.
  • A run that exhausts its budget stops and is labelled cut off (budget). Cost is calculated once and never changes again.

Record

  • Append-only audit log; every button press carries the name of whoever pressed it.
  • Nothing is physically deleted — there is no delete endpoint. Invalidated records are archived.
  • Experiments do not contaminate production: they record but do not distribute — no notifications, no briefs, nothing in the feed.

Security posture

One sentence for your security team: the data does not leave, the system only reads, every step is on the record.

  • Data is never copied. A read-only connection; analysis goes to the data. Personal data is processed in place.
  • Writing is technically impossible. Two separate locks: a grammar check before the query reaches the database, and a read-only connection.
  • Your credentials never reach us. They stay encrypted on your server; the runtime uses a pairing key and signed messages.
  • In doubt, the system stops. Fail-closed by design: exceeding a row limit is an error, not a silent truncation; no identity means no data.
  • Everything is recorded. Frozen budget and model per run; every object stamped with the identity that produced it.

Data sources

Phase 1 connectors

SQL data warehouses through the relational gateway, and SQL Server Analysis Services cubes through the SSAS gateway. Connector availability for your specific platform is confirmed in week one of the pilot, before anything else is scheduled.