Ian On Docs
Admin console

Database connections

Connect your company's PostgreSQL and MySQL databases so the AI can query them live, and control exactly what the AI may read and write.

In Admin → Database connections, you connect the PostgreSQL and MySQL databases your company runs to Ian On. The AI queries a connected database live whenever it needs to.

Database Connections is a feature that's off by default. If you don't see the menu, turn on Database Connections in Admin → Features.

Use the Database connections, Data access policies, PII masking rules, and Query audit log tabs at the top of the screen to manage and review connections, access rules, masking rules for sensitive information, and the query history.

Adding a connection

Press Add connection, enter the Connection string, and press Test and analyze schema. Ian On checks the connection, reads the schema, and fills in a draft Name and Description. Check the name and the description (required), then press Add connection. Whether it's PostgreSQL or MySQL is detected automatically from the address (postgresql://, mysql://, and so on).

If the AI can't draft a description, a notice appears. In that case, enter the Description yourself. When the analysis finishes, a Generate descriptions for N columns after adding (about M min) option appears. If you check it, the AI writes a description for each column that doesn't have one, one after another, once the connection is added. Progress shows on the expanded connection card, and you can Stop it while it runs.

The connection string is stored encrypted (AES-256-GCM) and is never shown again. To change it, enter a new value in Replace connection string on the connection's edit screen. For security, connection strings that point to localhost are blocked. Connection strings that point to private network addresses such as 10.x.x.x or 192.168.x.x are blocked too.

Press Show advanced settings to set the Scope to Organization-wide or One team. If you choose One team, also pick the team. The default is Organization-wide, and you can also change the scope on the connection's edit screen.

How the AI looks up data

With a newly added connection, the AI writes SQL to fit your question and queries the database live. The sync method, which copies rows into knowledge ahead of time, can't be set up for new connections.

The cards of connections created earlier with the sync method show Sync: Embeddings or Sync: Full. These connections don't sync automatically on a schedule. To bring the latest rows into knowledge, press Sync. The AI can't query a Sync: Embeddings connection directly.

Describing the schema (annotations)

To help the AI understand your tables, you can give each table and column a short description. Press a connection's name on its card to expand the schema list. A badge shows where each description came from: Manual, DB (a database comment), or AI (inferred). Use the pencil icon to edit a description yourself, or use Generate with AI next to a column to generate that column's description. Press Generate N above the list to generate descriptions for every column that doesn't have one, all at once. You can Stop it from the progress bar. With good descriptions, the AI understands a cryptic column name correctly instead of guessing.

Controlling access (permissions)

Use Permissions on the connection card to decide which agents and teams can use which tables. First add at least one permission. Then switch the Strict mode (block access without a grant) setting to ON and press Enable, and agents and teams without a permission can no longer use this connection. A connection with strict mode on gets a green STRICT badge, and its Permissions button shows a green shield. While strict mode is off, the permissions you add are only previews and don't take effect, except the ones given to personal agents. In this state, the Permissions button of a connection that has permissions shows in amber.

In Add permission, choose the Grantee type (agent or team) and the grantee. Allow every table in this connection is selected by default. If you uncheck it, type a table name into Allowed tables and press Enter to add it. To hide specific columns, enter them in the Blocked columns (optional; press Enter to add) field as table.column (for example, customers.email). When you're done, press Add permission.

Personal agents can use only the connections they've been given a permission for. For a personal agent, the permission's allowed tables, blocked columns, and write setting always apply, whether strict mode is on or off. The only personal agents in the grantee list in Add permission are the ones you created. For organization and team agents to query a connection, you also need to turn on Query databases in the Agents settings.

Letting the AI write

New connections are read-only. To allow writing, open the edit screen with the pencil icon on the connection card. Turn on Allow AI write operations and press Update. When you turn it on, a warning appears that data can be permanently changed. Once you save, the connection card gets an AI RW badge, and the AI can run INSERT / UPDATE / DELETE. On a connection with strict mode on, and for personal agents, the matching permission's Write permission must also be allowed.

To allow writing in a permission, press the Enable writing… button under Write permission in Add permission. You can't press this button while the connection's Allow AI write operations is off. Type GRANT-WRITE exactly, matching upper and lower case, and set a reason of at least 10 characters and an expiration (7 days, 30 days, 90 days, or permanent; 90 days by default). Press I understand — grant permission, then save with Add permission. After the expiration passes, that permission can no longer write.

Commands that change the schema (DROP / ALTER / TRUNCATE) are always blocked, even with writing turned on. If you allow writing, point the connection at a database user dedicated to that purpose instead of a powerful admin account.

Monitoring

Press Test to see whether the connection succeeds and how long it takes to respond. Press Refresh in the expanded schema list to re-read the schema and database comments from the live database. Once 24 hours have passed since the last refresh, Refresh recommended appears. Connections that use the old sync method also have Sync and Status buttons. Sync runs a sync once. Status shows, for each table, the number of rows synced, the last sync time, and any errors.

On this page