The chaos of letting LLMs touch production databases just got a safety net. Ariodb, a new source-available proxy released by developer Rooz Jalali, sits between AI agents and databases like Postgres, MySQL, MariaDB, and ClickHouse. It intercepts every SQL statement, enforcing strict policies that database grants alone can’t handle, such as per-agent table limits and row-count caps. The tool also records a journal of changes, allowing operators to undo a specific agent’s session without rolling back the entire database.

Intercepting the SQL Before It Hits the Wire

Ariodb doesn’t just read SQL text; it parses it using the database’s own engine. For Postgres, it uses the native parser to catch hidden writes inside constructs like EXPLAIN ANALYZE, PREPARE, and data-modifying WITH clauses. MySQL and MariaDB statements are cross-checked with a lexer, while ClickHouse gets a careful tokenizer. If the proxy can’t see inside a statement, it refuses it. This prevents agents from sneaking writes through complex queries or prompt injection attacks that trick the agent into executing destructive commands.

Enforcing Limits and Human-in-the-Loop Approvals

The proxy forces all reads to run in READ ONLY transactions, ensuring a 'read' query can’t secretly modify data. For writes, Ariodb measures the impact before committing. If an UPDATE affects more rows than a configured limit (e.g., 200 rows), the transaction is rolled back automatically. Riskier statements can be held for approval via a built-in dashboard, CLI, or integrations with Slack, Discord, and PagerDuty. It also supports using LLMs from Anthropic, OpenAI, or Gemini to judge statements against a written policy, adding a layer of automated governance.

Session-Level Undo for Agent Mistakes

Perhaps the most compelling feature for agent developers is the undo capability. Ariodb maintains a journal of before-and-after images tagged by agent session. If an agent goes rogue or makes a logical error, an operator can reverse that specific session’s changes in one transaction. The system detects conflicts if other users modified the same rows in the meantime, reporting them rather than silently overwriting data. This granularity is crucial for debugging agent behavior in shared environments.

Current Limitations and Compatibility

Ariodb is currently at version 0.1.0, marking its first public release. While it supports Postgres 14-18 and MySQL 8.4 fully, ClickHouse writes are judged before running and cannot be rolled back or undone due to the database’s lack of transactions. The tool is a single Rust binary with a built-in dashboard, licensed under the Sustainable Use License. This license allows internal business use but prohibits selling Ariodb as a hosted service or product without a separate agreement.

Key Takeaways

  • Ariodb acts as a proxy that parses SQL using native database engines to prevent hidden writes and prompt injection exploits.
  • It enforces row limits and table access per agent, rolling back writes that exceed configured thresholds before they commit.
  • The tool supports session-level undo, allowing operators to reverse an AI agent's changes without affecting other users' data.
  • Approvals can be routed to humans via chat tools (Slack, Discord) or judged by LLMs against custom policies.
  • Current limitations include no undo support for ClickHouse and a weaker write check for MySQL/MariaDB compared to Postgres.

The Bottom Line

Ariodb is a necessary evolution for agentic AI infrastructure. As we move from 'chatbots' to 'agents' that take actions, the blast radius of a hallucination is no longer just a wrong answer—it's a dropped table. This tool provides the guardrails we’ve been missing.