dbt Summit

Beyond vibe governance: keeping sensitive data out of your agent's context window

Wednesday, September 162:00 PM PT
Level 4, Discovery Hall Theater

The moment an agent calls a tool — say, running a query through the dbt MCP server — whatever comes back (customer emails, health records, account numbers) lands in the model's context window, and there's no taking it back. Every test, contract, and grant you've written sits upstream of that moment. I've worked with multiple customers who hit this wall: they wanted conversational access to systems full of sensitive data without polluting the context window.

Most teams improvise their way through this: a "don't reveal PII" line in the system prompt, a regex scrubber, hope. We call it vibe governance: relying on prompts to control agents that execute at machine speed, without the judgment a human would apply. The fix isn't a better prompt or skill. It's enforcement between tool output and model context.

This talk is based on my experience with multiple teams: what they tried first, where they stumbled, and where they settled — and how the same pattern turns the dbt MCP server into a governed resource, driven by the sensitivity metadata already living in your dbt project. You've governed your data at rest. The context window is where governance leaks now.

Check out more sessions

View all sessions
dbt Summit on stage

Ready to join us?

Join data leaders and practitioners at dbt Summit for three days of ideas, skills, and shared progress.