The model writes specs, not data
Generation is bound to a shared Zod schema, so the model emits a visualization specification — SQL plus chart configuration. Real metric values are only ever produced by the server executing guarded SQL. How it works

The model writes specs, not data
Generation is bound to a shared Zod schema, so the model emits a visualization specification — SQL plus chart configuration. Real metric values are only ever produced by the server executing guarded SQL. How it works
All model SQL is untrusted
SELECT-only, single statement, catalog allowlist, no comments, no time or non-deterministic functions — re-validated on every save and every execution. Invariants
The server owns time
The IR carries relative expressions like now-15m, but the server resolves
them and injects the bounds as bound parameters. The model cannot choose
the window or the row limit. Executing a panel
Panels carry only an opaque id
No host, port, database, or credential ever lives in a spec. The registry
owns the connection config and a secret_ref resolved from the server
environment. Secret references