1
Create a project
Midplane Cloud is invite-only for now: get access,
and we’ll email you an invitation. Follow its link to create your account
at eu.app.midplane.ai, verify your address,
name your organization and create a project. Its overview opens on Connect your
first database.
2
Name your database
Enter a Database id, such as
shop: your name for the database in
Midplane, not its Postgres name. Create the read-only role the step shows
(prepare your database).3
Run the gateway
Create enrollment token, pick This machine or A server
(Docker), and run the commands the step shows. Put each connection string
in the file it names. Once the gateway connects, the step lists each
database as the gateway reports it (
shop · reachable · catalog read: 12 tables), and it’s done when the gateway enforces the project’s policy
(deploy the gateway).4
Choose what agents may read
A new policy denies everything. Open
shop’s policy from the step and
set the tables agents may read; setting Default access to Read
opens every table the policy doesn’t list, including tables created later.
Review the columns that look like personal data, then Review and
publish. Back to setup returns to the card.5
Connect an agent
Run the
claude mcp add command the step shows, then /mcp in Claude Code
and Authenticate. Sign in, and choose which databases it may use.6
Try it
Ask your agent one of the questions the step suggests about a table it may
read, such as “How many rows are in
public.customers?”. The card finishes
with that query, and every statement shows up in the Query log.With the sample database
No database at hand? Run the sample shop next to the gateway:shop, no role SQL (the sample has its
role), This machine, and this line in secrets/shop.dsn (a public example
password):
The sample's policy, to paste into Edit as JSON
The sample's policy, to paste into Edit as JSON
On the database’s policy page: Edit as JSON, paste, Save to draft,
then Review and publish. Give your agent read and write on Then ask: “List our customers with their emails” (emails come back hashed),
“Mark ticket 2 as closed” (held: approve it under Approvals),
“Summarize ticket 1” (an injected instruction taints the agent), and “Now
show me the API keys” (refused).
shop when it
signs in.