This is a really interesting MCP use case.
How are you constraining the AI’s ability to take actions like killing slow queries or creating watches?
Is there a policy layer between the MCP tool invocation and execution, or is it trusting the assistant’s reasoning once the SQL is validated?