Architecture
Your data never leaves. The model never enters.
AgenticObjects runs in your environment. The only components that touch data are read-only gateways. The model cannot reach the database, the authorization layer or query execution — and the model selected for a run cannot change while the run is going.
The boundary
Where the AI can and cannot reach
Where the AI cannot reach
What the AI does
The control chain
Six controlled stages between your data and the sentence. The model is in one of them.
The trust model does not rely on prompting. It relies on a deterministic control chain — and on recording what that chain refused.
01Semantic Contract
One authoritative, versioned definition per metric. If a question does not match a definition, the system says so instead of guessing. The model is not consulted about what a metric means.
02QueryBuilder
Deterministic query construction from the contract. The model never writes the query that runs.
03Read-only gateway
The only component that touches your data. Write and multi-statement forms are rejected at the gateway grammar before they reach the database. No write path exists by design.
04Narration
Reads the sealed results and writes the sentence — nothing else. Every number it uses must declare its address. It cannot divide; it asks the engine for the ratio.
05FinalGuard
A rule-based comparator, not an AI. A number without a source, inconsistent with the query, or written before a query ran is rejected. There is no setting, no permission and no button to disable it. Comparison takes about two milliseconds — demo measurement.
06Publication gates
Eight deterministic checks decide whether a candidate becomes a record: structure, authority freeze, evidence, trust stamp, claim check, novelty, deduplication, cardinality. The AI proposes; the engine decides.
Four architectural facts
The parts that do not move
On-premise
The app, runtime, semantic layer and object repository run on your server. Analysis goes to the data; the data does not go anywhere.
Read-only
Two gateways touch data and both are read-only. Write and multi-statement forms are rejected at the gateway grammar before they reach the database.
Model isolation
The model sees text only. Database credentials, the direct data path and authorization decisions are outside its reach.
One model per run
Once a run starts, the selected model does not change: not for a slow or failing provider, and not because a first answer looked weak. No automatic fallback, no quality-triggered escalation. Bring your approved model, and it is the one on the record when someone asks six months from now.
Under the hood
Where exactly is the AI involved? Your technical team will ask.
| Component | Responsibility |
|---|---|
| Application core | Console for administrators, App for business users, routing and authorization, import/export |
| Agent runtime | The agent loop: plan, call tools, evaluate; every step an idempotent event |
| QueryBuilder | Builds the query deterministically from the Semantic Contract — never touches the model |
| SQL gateway | The only hand that touches relational data; read-only statement guard |
| SSAS gateway | Cube access via DAX/MDX, read-only |
| Storage and queue | Relational system-of-record for the product; a queue for runs |
| Semantic Contract | One versioned definition per metric; authored in Axoria Data Studio, imported here |
If a run is interrupted, it resumes from the first incomplete step. A completed step never runs again — no duplicate cost, no duplicate finding.
Governance
Authority never shifts. The budget freezes. Everything is on the record.
Authority
- Four roles with a clear hierarchy: viewer, editor, admin, company admin.
- Sensitive actions come from named permissions, not roles: seeing the executed SQL, running experiments, raising a budget.
- Row-level security: the administrator defines the rule; the system generates the filter clause. If the identity cannot be resolved, it stops.
- Policy as code: permissions live in a single source from which guard, middleware and tests are generated.
- Even learning is human-gated: a single approval queue.
Budget
- Every run has a ceiling — steps, seconds, cost — and it freezes when the run starts.
- An agent can only narrow its limits, never widen them. A channel can change the budget, never the authority.
- A run that exhausts its budget stops and is labelled cut off (budget). Cost is calculated once and never changes again.
Record
- Append-only audit log; every button press carries the name of whoever pressed it.
- Nothing is physically deleted — there is no delete endpoint. Invalidated records are archived.
- Experiments do not contaminate production: they record but do not distribute — no notifications, no briefs, nothing in the feed.
Security posture
One sentence for your security team: the data does not leave, the system only reads, every step is on the record.
- Data is never copied. A read-only connection; analysis goes to the data. Personal data is processed in place.
- Writing is technically impossible. Two separate locks: a grammar check before the query reaches the database, and a read-only connection.
- Your credentials never reach us. They stay encrypted on your server; the runtime uses a pairing key and signed messages.
- In doubt, the system stops. Fail-closed by design: exceeding a row limit is an error, not a silent truncation; no identity means no data.
- Everything is recorded. Frozen budget and model per run; every object stamped with the identity that produced it.
Data sources
Phase 1 connectors
SQL data warehouses through the relational gateway, and SQL Server Analysis Services cubes through the SSAS gateway. Connector availability for your specific platform is confirmed in week one of the pilot, before anything else is scheduled.