Local query gate · specimen no. 001

Let tools query the database. Keep a signed trail.

Put a small, read-only boundary in front of SQLite: named templates pass within limits, novel SQL waits for a human, and every attempt leaves a verifiable receipt—not a copy of the data.

cargo install db-access-receipts
A pressed fern whose fronds become orderly rows of database cells beside a blank accession tag
Fig. 1 — A query identified, bounded, and recorded without preserving its returned specimen.

Interactive field test

Follow one query to its receipt.

This browser walkthrough is illustrative and local-only. The real CLI uses SQLite's read-only mode and Ed25519 signatures.

A · Identify query

Hashed in the receipt, never stored raw.

Local receipt notebook

No demo receipts yet. Run the specimen above to begin.

No receipt pressed yet

Run a query. Allowed, denied, and failed attempts all leave evidence.

Method, not middleware

Three checks. One durable artifact.

Your client or agent invokes one binary. Credentials and query results stay on the machine.

Classify

Reviewed templates run with declared parameters. Novel reads require an attached terminal and a randomized challenge.

Bound

SQLite opens read-only. Multiple statements and writes stop. Column caps reject; row caps truncate safely.

Press

Every outcome records actor, hashes, limits, counts, approval path, and Ed25519 signature—never result data.

db-receipts query \
  --template open-orders \
  --param account_id=acct_123 \
  --actor analyst@team

# Verify later, without database access
db-receipts verify .db-receipts/receipts/20260827T211400Z-….json

Team field kit

Roll it out without inventing the process.

$39 one-time purchase

The CLI, receipt verification, safety controls, and your data remain free and local. The paid kit adds the rollout method.

Sociobot/Dodo is the merchant of record. Refunds are handled there and revoke the license automatically. See privacy and terms.