Answer lineage: auditing what an AI agent actually read
The chat transcript records what was said, not what was true. Lineage links an answer to the definition and data behind it.
7 articles
The chat transcript records what was said, not what was true. Lineage links an answer to the definition and data behind it.
A dashboard answers the question already asked; an MCP server answers the one nobody anticipated. Both read the same definition.
Access, definition, freshness and provenance, decided before the question. Connection is solved; trust is what nobody shipped.
The spec makes tools model-controlled and tool annotations untrusted. Your tool surface is the security boundary.
MCP makes authorization optional, and 40.55% of live remote servers expose tools with none. Safety is what you add on top.
Fivetran's own FAQ answers 'Do I need MCP?' with 'No. MCP is one option.' They are layers, not rivals. The real difference is governance.
Row-level security fails at the role the agent connects with. Per-tenant isolation moves the boundary out of application code and into architecture.