By NHI Mgmt Group Editorial TeamBased on WorkOS: “Datadog: SQL Is the New Bash for AI Agents” (December 12, 2025)

TL;DR: Datadog's MCP demo showed that agents complete observability investigations faster with SQL than with freeform tool chains, because structured queries reduce context-window bloat and keep aggregation at the data layer, according to WorkOS. The broader lesson is that AI agent interfaces need precision and scoping, not just more tool access.


At a glance

What this is: This article argues that SQL is a better MCP interface for AI agents than freeform tools because it lets agents query, filter, and aggregate observability data more precisely and with less context overhead.

Why it matters: For IAM and security teams building agentic workflows, the core issue is not just tool access but how tightly agent actions are scoped, expressed, and audited when they query operational data.


Context

The governance gap here is not query capability alone. It is the assumption that an AI agent can safely work through multi-step, freeform tool chains without losing precision, context, or control over what it has actually asked the system to do.

SQL becomes relevant because it shifts the interaction from procedural back-and-forth to a declarative request. For agentic workflows, that changes how runtime decisions are expressed, how intermediate state is handled, and how much ambiguity the interface leaves for the model to improvise with.


Key questions

Q: How should teams design MCP interfaces for AI agents that need data access?

A: Design around narrow, declarative interfaces that return completed answers rather than raw fragments. Structured queries reduce context bloat, make outcomes more predictable, and keep sensitive operations easier to observe and govern than open-ended tool chains. The practical goal is to shrink the action space without making the agent useless.

Q: Why do freeform tool chains create more risk for AI agents than SQL queries?

A: Freeform chains force the agent to guess syntax, manage intermediate state, and stitch together results across multiple calls. That increases context use, expands the chance of error, and makes the final outcome harder to reason about. SQL centralises the work in the data layer, where execution is more deterministic and auditable.

Q: What are the signs that an agent interface is too loosely scoped?

A: Look for repeated tool calls, growing prompt length, fragile parsing steps, and agents that need several hops to answer a simple analytical question. Those are symptoms that the interface is making the model do the database's job. A better design gives the agent one precise request and one reliable result.

Q: What is the difference between giving an agent access to data and giving it query authority?

A: Data access means the agent can reach a system or dataset. Query authority means it can shape what it asks for, which can be much broader or narrower than the underlying credential suggests. Good governance controls both, because a well-authenticated agent can still overreach through overly expressive queries.


Technical breakdown

Why structured queries work better than freeform tool chains

Freeform tool use forces an agent to simulate a shell workflow: inspect a little data, infer the next step, call another tool, and retain state across each hop. That pattern is expensive in context and brittle at scale, especially when the underlying task is exploratory analysis over large observability datasets. SQL compresses the entire intent into one statement, so the execution engine, not the agent, handles filtering, projection, and aggregation. In MCP terms, the interface becomes a constrained contract rather than a conversational sequence of guesses.

Practical implication: prefer declarative interfaces when you want agent actions to stay compact, repeatable, and easier to govern.

How SQL changes aggregation and retrieval for agents

Aggregation is where the architectural difference becomes obvious. A freeform tool loop usually pulls raw rows into the agent context, then asks the model to count, group, or compare records itself. SQL moves that work to the data layer, where indexes and query planners can execute GROUP BY, COUNT, and selective scans efficiently. That improves correctness because the database performs the operation against the source of truth, not an approximation assembled in model context. It also reduces the chance that an agent hallucinates from partial samples.

Practical implication: move summarisation and counting into the system of record instead of asking the agent to reconstruct them from raw outputs.

What SQL means for MCP interface design

The article points to a broader pattern in agent design: successful MCP interfaces often look less like open-ended toolkits and more like controlled query surfaces. That matters because AI agents are reliable only when the action space is narrow enough to generate consistently and broad enough to answer the task. SQL hits that balance for data-heavy workflows. It does not eliminate risk, but it reduces the ambiguity that arises when an agent must invent execution steps, interpret bespoke syntax, and manage transient results across multiple tool calls.

Practical implication: treat interface design as a governance control, not just a developer convenience, when exposing systems to agents.


NHI Mgmt Group analysis

Declarative interfaces are becoming the governance boundary for agentic workflows. The article shows that SQL is not just faster, it is more governable because it constrains what the agent can express at runtime. That matters for identity programmes because the control point shifts from multi-call execution to a single, reviewable request. Practitioners should treat the query surface as part of the trust boundary.

Freeform tool chains create context debt for agents. Every extra filter, transformation, and intermediate lookup consumes context and increases the chance of drift between intent and execution. The more the agent has to improvise, the less predictable its behaviour becomes. The practical consequence is that platforms exposing data to agents need narrower, semantically explicit interfaces if they want reliable outcomes.

SQL as an MCP interface sharpens the difference between access and authority. An agent can be given the ability to ask precise questions without being given broad operational discretion. That distinction matters across NHI and agentic AI governance because the safest interface is not the most powerful one, but the one that keeps action scope legible. Teams should design for answerability first and flexibility second.

Agentic access control has to account for query semantics, not only credentials. A well-authenticated agent can still create risk if it can ask overly broad questions, chain requests unpredictably, or reconstruct sensitive state from many small queries. The article reinforces that privilege is expressed not only through tokens but through the shape of the interface itself. Security teams should govern what an agent can express as much as what it can reach.

Structured querying is becoming a pattern for agent containment. The more an agent depends on declarative requests, the easier it is to define scope, observe intent, and trace outcomes. That does not remove the need for lifecycle control over machine identities and tokens, but it reduces the variance that makes freeform automation difficult to trust. Practitioners should see SQL-like interfaces as containment, not convenience.

From our research library:

What this signals

Query shape is becoming a control surface for agentic systems. When agents rely on structured queries, teams can govern what the agent can express instead of trying to inspect every intermediate reasoning step. That is a cleaner operating model for observability, incident response, and any other data-heavy workflow where freeform chaining would otherwise dominate.

Structured retrieval reduces governance friction across identity programmes. Agents that receive complete answers from the data layer are easier to scope, log, and review than agents that must assemble results from many partial tool calls. For practitioners, the design question is no longer whether the agent can reach the system, but how much ambiguity the interface allows.

SQL-like interfaces are a practical containment pattern for AI agents. They do not eliminate the need for lifecycle governance, token control, or auditability, but they do make runtime behaviour more legible. Teams should expect more agentic workflows to converge on constrained, declarative access patterns because that is where reliability and oversight start to align.


For practitioners

  • Constrain agent access to declarative query surfaces Expose SQL or similarly structured interfaces for high-volume data tasks instead of giving agents open-ended procedural tools that require step-by-step improvisation.
  • Separate retrieval from reasoning Keep aggregation, filtering, and counting in the system of record so the agent receives finished results rather than raw data fragments it must reconstruct.
  • Review agent tool scopes for query breadth Limit the fields, tables, and dimensions an agent can request so the interface does not allow broad or ambiguous data discovery by default.
  • Instrument agent query activity for review Log the exact SQL statements and result sets so incident review can show what the agent asked, what it received, and whether its scope stayed within policy.
  • Use interface design as a control Treat the shape of the MCP endpoint as part of access governance, with explicit boundaries on what can be expressed, not just who can authenticate.

Key takeaways

  • Structured queries make AI agent investigations more predictable because the execution engine handles filtering and aggregation instead of the model improvising each step.
  • The main governance issue is interface scope, not just authentication, because agents can overreach through expressive query patterns even when credentials are controlled.
  • Teams that expose data to agents should prefer declarative surfaces, log exact requests, and keep transformation work in the system of record.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10, OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI02 — Tool MisuseThe article centres on agents selecting and using tools through a constrained interface.
ASI03 — Identity & Privilege AbuseThe governance problem is scope, not only access, because agents can overreach through expressive queries.
Recommendation — Constrain agent tool use to explicit query actions and prevent open-ended tool chaining. Limit the privilege expressed through agent query surfaces and review scope against intent.
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationMCP access still depends on machine identity authentication before structured queries are executed.
NHI-05 — Overprivileged NHIThe article's core risk is excessive query scope, which maps to overprivileged non-human access.
Recommendation — Apply strong machine authentication before exposing any agent query interface. Reduce agent permissions to the minimum fields, tables, and actions required.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is about controlling what an AI agent is allowed to query and aggregate.
Recommendation — Define and enforce least-privilege entitlements for agent-facing data interfaces.
MITRE ATT&CKTA0006;TA0007 — Credential Access; DiscoveryOverbroad agent interfaces can support credentialed discovery of sensitive data patterns.
Recommendation — Map broad agent query capability to discovery risk and monitor for unusual data exploration.

Key terms

  • Declarative Query Language: A declarative query language describes the result you want and leaves the execution plan to the system. In security operations, that usually means cleaner searches and easier review, because the analyst specifies intent while the platform handles filtering, scanning, and ordering.
  • Context bloat: The accumulation of tool definitions, schemas, and metadata in an agent’s working context until reasoning capacity is consumed by exposure rather than task execution. It matters because too many connected tools can reduce performance, obscure intent, and make access governance harder to reason about.
  • Query Authority: Query authority is the effective scope of what an identity is allowed to ask for, not just what it can technically reach. For agents, this matters because an authenticated identity can still overreach if its query language allows broad discovery, aggregation, or reconstruction of sensitive information.
  • Transport Tooling: Software used to move changes, packages or archives through deployment pipelines and into production systems. Because these tools can influence release state and privileged workflows, they need the same access control and integrity review as runtime services.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 7, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org