How data access works
OpenNeko queries approved business data through GraphJin. The agent receives tools for the exposed schema; it does not receive a raw database password or an unrestricted SQL shell.
- Use a dedicated, least-privilege database account for each source.
- Expose only the schemas and operations the deployment needs.
- Treat write access as an action: scope it, log it, and require approval where the consequence warrants it.
Connect a source
- Create a read-only database account on the source system.
- Place GraphJin close to that database and configure the approved schema.
- In OpenNeko settings, add the GraphJin endpoint and verify the connection.
- Test a narrow question and inspect the returned source data before broadening access.