read_only keeps only the tools that look, and features picks the Raff products. An app cannot call a tool it was never given, so these are the simplest way to limit an assistant.
How it works
Read-only mode
Add?read_only=true to the URL:
run_sql.
run_query stays, and refuses any statement that writes.
Tool groups
Add?features= with the groups you want, separated by commas:
Without
features, every group is loaded. An unknown group name is refused, so a typo does not silently load nothing. New groups (apps, functions, servers) are added as they ship; a URL that names its groups keeps exactly those.
Both together
When to use it
- Read-only: letting an assistant explore a production database, explain slow queries or write reports, with no way to change data or spend money.
- Tool groups: keeping the tool list short in apps that slow down or get confused with many tools, or keeping documentation search out when you only want account tools.
- Both: a shared team assistant that answers questions about live databases.
Trade-offs
- These options are part of the URL you add in the app. Anyone who can edit the app’s connector settings can remove them; for a hard limit, also use a member role or an API key without write permissions. See Sign-in and access.
- An app connected twice (once read-only, once full) sees both sets of tools and may pick either.
Related
Tools
Which tools are read-only and which change things.
Paid changes
Confirmation before anything is charged.