What you can recommend
Your client is asking to move agents into production against real data. Prompt and usage controls lower the probability of a bad request. They do not tell you what reached the data. We produce that record, so the residual risk you are being asked to accept becomes something you can measure.
What you get in an investigation
When you are called in, the first question is scope. Today that answer is assembled from an application log showing a connection, a platform record showing a truncated result, and a database log showing one shared service account. We give you the statement as executed, the rows returned, the columns read, and a signature that shows the record was not altered afterwards.
How a pilot works
One client, one PostgreSQL estate, one non critical service. Deployment is a connection string change. Tool-call refusal is switched on in the first deployment, while database-path refusal remains off. The output is a report on the client's own traffic, written for whoever signs the risk acceptance, and it includes the share of traffic that could not be classified.