<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><description>Permission before production writes. · Pilot $100 · Gateway $299/mo · Discord: https://discord.gg/SAD4ZBWqv · https://sqlguard.io</description><link>https://bsky.app/profile/sqlguard.bsky.social</link><title>@sqlguard.bsky.social - SQLGuard</title><item><link>https://bsky.app/profile/sqlguard.bsky.social/post/3mrzijnz4ec2b</link><description>Postgres MCP servers that default to unrestricted read/write still leave one question open: was this exact agent SQL authorized before it ran?&#xA;&#xA;Role access ≠ statement authorize. Authorization Receipt is the gap.&#xA;&#xA;sqlguard.io/challenge</description><pubDate>01 Aug 2026 12:41 +0000</pubDate><guid isPermaLink="false">at://did:plc:45dk6nef4jcnlg3v3uffagdp/app.bsky.feed.post/3mrzijnz4ec2b</guid></item><item><link>https://bsky.app/profile/sqlguard.bsky.social/post/3mryq7uufzs2b</link><description>Access tools answer who has credentials. Logs answer what happened.&#xA;&#xA;The missing question for AI agents writing SQL: was this exact action authorized before it happened?&#xA;&#xA;Felt DENY → prove at $0 → Graduate Exact $100 (or Gateway $299/mo). Not a security scan.&#xA;&#xA;sqlguard.io/challenge</description><pubDate>01 Aug 2026 05:26 +0000</pubDate><guid isPermaLink="false">at://did:plc:45dk6nef4jcnlg3v3uffagdp/app.bsky.feed.post/3mryq7uufzs2b</guid></item><item><link>https://bsky.app/profile/sqlguard.bsky.social/post/3mrymoemk4c2b</link><description>For agents that crawl first: one JSON index for MCP, A2A, and the authorize path before production SQL writes. sqlguard.io/discover — lint still is not change control.&#xA;https://sqlguard.io/discover</description><pubDate>01 Aug 2026 04:22 +0000</pubDate><guid isPermaLink="false">at://did:plc:45dk6nef4jcnlg3v3uffagdp/app.bsky.feed.post/3mrymoemk4c2b</guid></item><item><link>https://bsky.app/profile/sqlguard.bsky.social/post/3mrxlnayrnc2q</link><description>OAuth can identify the caller. Database roles can limit scope. There is still a separate question: was this exact production write approved?&#xA;&#xA;That is the small control gap we are working on. If useful, the challenge demo shows the flow:&#xA;sqlguard.io/challenge</description><pubDate>31 Jul 2026 18:31 +0000</pubDate><guid isPermaLink="false">at://did:plc:45dk6nef4jcnlg3v3uffagdp/app.bsky.feed.post/3mrxlnayrnc2q</guid></item><item><link>https://bsky.app/profile/sqlguard.bsky.social/post/3mrxkrnuglk2k</link><description>Lint can flag risky SQL. It cannot authorize a production write.&#xA;&#xA;SQLGuard issues a verifiable execution certificate before mutation, then requires verification before execute.&#xA;&#xA;Authorize ≠ lint.&#xA;sqlguard.io/trust&#xA;sqlguard.io/challenge</description><pubDate>31 Jul 2026 18:16 +0000</pubDate><guid isPermaLink="false">at://did:plc:45dk6nef4jcnlg3v3uffagdp/app.bsky.feed.post/3mrxkrnuglk2k</guid></item></channel></rss>