Product1 publisher3 min readPublished
CData's gateway holds AI agents to each user's own row and column permissions
CData's Connect AI Gateway, now in early access, holds AI agents to each user's own permissions down to specific rows and columns. Teams deploying agents can now buy that control, though the accuracy claims behind it come from CData's own tests.
The Product Desk · Product desk

What happened
- Every agent response comes with an audit trail recording which prompt, model, tool and policy contributed to it.
- A context engine can reuse business definitions teams already maintain in dbt and Power BI, along with field and relationship details from source systems.
- Corrections and informal knowledge from documents and conversations sit in a context graph outside any one model, and people decide what becomes shared context.
- In a company-run test of 378 enterprise queries, CData said Connect AI answered 98.5% correctly, against 65% to 75% for other MCP providers it tested.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- capability When an agent answers wrong or has an action blocked, an administrator can follow the request from the first prompt through model choice, data retrieval and the action itself.
- decision Model choice and token spend become policies IT sets centrally, so individual agent builders stop making that call for themselves.
- constraint Teams whose revenue definitions live only in a data catalog cannot hand them to the first release directly, so the shared-definition benefit depends on what already sits in dbt or Power BI.
CData's own example of the problem is an employee who asks an agent for "revenue" and gets a different result depending on which systems and calculations the agent chose [6]. "You don't want AI redefining revenue every time you ask a question about revenue," said Marie Forshaw, CData's senior vice president of product marketing [9].
I'd expect many rollout plans to treat the agent as one more analyst with one set of access. In use, the agent works for whoever is typing [3]. CData's gateway is built for that second case. It uses the company's connectors to hundreds of business applications and databases to apply the asking person's permissions whenever an agent retrieves data or takes an action for them [3]. IT registers the models, MCP servers and agents in one place and sets rules for each [2]. So two employees with different entitlements can ask the same question and get different rows back [3][4].
CData's accuracy numbers are its own. The test covered Connect AI, the platform the new gateway extends [1]. Across 378 queries, CData's reported rates work out to about 6 wrong answers for Connect AI and roughly 95 to 132 for the other MCP providers it tested [1][2]. A second CData test found up to a 175-fold cost difference between models that reached the same correct answer [14]. SiliconANGLE, which reported the launch, noted that these are CData benchmarks, not independent tests or documented savings from a customer deployment [15].
Cost control starts as policy. The gateway can set token budgets and route requests according to policies [10]. "Initially, it's going to be based on policy," said Will Davis, CData's chief marketing officer. "Eventually, it will be intelligent enough to see the prompt, see the system behavior, and be able to select the lowest-cost model that connects to the task." [11] CData said its data layer can also filter, join and aggregate records before passing a result to a model, to cut how much data lands in the context window [12].
CData is keeping the context engine narrow. Executives said it can import definitions from analytics products but is not meant to replace a full data catalog or semantic layer [17]. "We by no means want to be the be-all and end-all of a catalog," Davis said [19].
For a team weighing this against its own build, two facts about the deployment settle most of the choice: whether employees see different rows of the same tables, and whether agents only read or also act.
- Same access for everyone, read-only agents: per-user enforcement adds little. The case rests on shared definitions and on accuracy figures only CData has measured [15]. - Different access, read-only agents: row and column policy is what you are buying [4]. The first check is two users with different entitlements asking the same question. - Same access, agents that act: the audit trail matters most, because a wrong or blocked action is what someone has to explain on Friday [5]. - Different access, agents that act: every part of the gateway applies, and so does the fact that it has only entered early access [1].
What to watch
- An independent test or a named customer deployment that reproduces CData's accuracy figure or its token savings outside the company's own benchmark.
- Pricing and a general-availability date for Connect AI Gateway, the two things a buy decision needs that early access does not settle.
- Whether CData ships the automatic lowest-cost model selection and direct data-catalog import it describes as planned.