Beyond vibe governance: keeping sensitive data out of your agent's context window
The moment an agent calls a tool — say, running a query through the dbt MCP server — whatever comes back (customer emails, health records, account numbers) lands in the model's context window, and there's no taking it back. Every test, contract, and grant you've written sits upstream of that moment. I've worked with multiple customers who hit this wall: they wanted conversational access to systems full of sensitive data without polluting the context window.
Most teams improvise their way through this: a "don't reveal PII" line in the system prompt, a regex scrubber, hope. We call it vibe governance: relying on prompts to control agents that execute at machine speed, without the judgment a human would apply. The fix isn't a better prompt or skill. It's enforcement between tool output and model context.
This talk is based on my experience with multiple teams: what they tried first, where they stumbled, and where they settled — and how the same pattern turns the dbt MCP server into a governed resource, driven by the sensitivity metadata already living in your dbt project. You've governed your data at rest. The context window is where governance leaks now.
Check out more sessions
- Hands-on lab
Migrate stored procs with dbt Wizard
Raini Laughlin / dbt LabsSteven Nguyen / dbt LabsView session - Breakout session
AI-powered data development: How agentic SDLC & dbt-MCP transformed our data engineering workflow
Suhas Jangoan / ZendeskAyan Putatunda / ZendeskView session - Keynote
Keynote: Level Up
Tristan Handy / Fivetran + dbt LabsGeorge Fraser / Fivetran + dbt Labs9 more speakersView session
