RAG, Done Safely: Chat With Your Database Without Leaking It
Sep 25, 2026
Row-level security stops the wrong ROWS from leaking. It says nothing about the wrong FIELDS. This build-along closes that gap: Tom takes a RAG chatbot that can already answer questions about a shared notes wall, locks it down so each person only ever retrieves rows they're allowed to see — then goes further and adds PII redaction so sensitive fields never reach the model in the first place, with Claude Code writing the fix live.
You'll see: why "the model only retrieves what you're allowed to see" isn't the whole story, a real Postgres row-level-security policy added end to end, PII redaction added with one prompt and tested against real data, the trade-offs Tom flags honestly along the way ("would I ship this? Absolutely not" — and why), and where this fits with the two earlier builds in the series.
Chapters:
0:00 RAG, Done Safely: Chat With Your Database Without Leaking It
1:40 Row-Level Access, Then PII Redaction
2:56 Locking It Down to Row-Level Access
4:05 "Don't Let It Walk Out the Back Door"
10:48 I Have 2 Notes. The Wall Has 34.
12:33 Adding PII Redaction With One Prompt
13:56 Testing PII Redaction End to End
19:41 Hiding It in the UI
22:12 The PII Redaction Reveal
24:11 Would I Ship This? Absolutely Not.
25:09 Where to Go Next
Is your AI agent actually ready for real data and real production traffic? Concept To Cloud's free AI-Readiness Audit tells you exactly where the gaps are — book a Discovery call:
https://concepttocloud.com/services/ai-data-preparation/ai-readiness-audit
---
Concept To Cloud helps regulated and mid-size teams take AI agents from toy demo to production — real data sources, guardrails, and a plan for what happens when things break. concepttocloud.com
Show More Show Less #Arts & Entertainment

