How do you enforce tenant isolation with that method, or prevent unbounded table reads?
We do something similar for our backoffice - just with the difference that it is Claude that has full freedom to write queries.
We do something similar for our backoffice - just with the difference that it is Claude that has full freedom to write queries.