In development, waitlist open

The agent can have Postgres.
You keep the undo.

A self-hosted Go proxy between your coding agent and Postgres. It'll hold DROP, TRUNCATE and unscoped writes for your approval, snapshot the affected tables first, and restore them with one command. Not built yet, I'm writing it now.

One email when early access opens. No drip sequence.

You're on the list. Tell the next person who posts a dropped-prod thread.

Share on X

The problem

You gave the agent a database URL so it could actually fix things.

Then it decided the users table looked like leftover test data. Same cause every time: the agent had the real credentials, and the only guardrail was text in a prompt.

Why now: this is already happening in public. Replit's agent deleted a company's production database in July 2025, and a Cursor agent wiped a startup database in April 2026. I'll post progress on X.

Read-only MCP

Safe, until the agent needs to fix what it just diagnosed, and you're pasting SQL by hand.

CLAUDE.md rules

Suggestions. The model ignores them the moment a cleanup looks obvious.

Nightly pg_dump

Last night's dump, a restore you've never run, and every write since midnight gone.

How it works

Hold, approve, snapshot, restore.

The agent gets a Tablebelt connection string and the app keeps the real one, so Tablebelt is never between your users and the database.

How it connects interface we're building
# Point the agent at Tablebelt, not Postgres
DATABASE_URL=postgres://agent@127.0.0.1:5439/app

# App keeps the real URL, off the agent host
# postgres://app@db.internal:5432/app
Postgres only Fail closed

The agent issues SQL

DROP TABLE users; hits Tablebelt, not Postgres. Same for TRUNCATE, unscoped DELETE, and ALTER that drops a column.

Destructive SQL is held

If the statement is destructive, or it can't be parsed, it doesn't run. The agent gets a structured error it can explain back to you.

Approve from your phone

You get a ping with the exact statement. Approve and Tablebelt snapshots the affected tables, then runs it. Deny and the agent is told no. Free approves in a local CLI.

Undo is one command

tablebelt restore snap_id puts those tables back as they were at snapshot time. It's not point-in-time recovery for the whole database. Writes after the snapshot are lost.

tablebelt restore mock-up, target feel
$ tablebelt restore snap_0001
restoring  public.users from snap_0001
ok         public.users
note       writes after snapshot are gone

What it catches

What it holds

Parser-based, not a denylist of string prefixes. If Tablebelt can't read it, it doesn't run it. The exact parser is still coming.

DROP TABLE / SCHEMA / DATABASE

Gone, and no migration file brings the rows back.

TRUNCATE

Every row in one statement, with no WHERE to scope it.

DELETE / UPDATE

Held when there's no WHERE. Scoped writes can still go through. I haven't decided yet how to treat WHERE 1=1 or other tautologies.

ALTER ... DROP

Columns and tables you can't get back from a migration file the agent also rewrote.

DISABLE ROW LEVEL SECURITY

Nothing is deleted, but every row is suddenly readable by whoever has a key.

unparsed SQL

If it can't be parsed it doesn't run, because production isn't the place for a best-effort guess.

Works with

Built for the agents and hosts you already use.

It works over the Postgres wire protocol, so it doesn't care who hosts the database.

Planned support

Agents

Claude Code Codex Cursor Any MCP client

Postgres hosts

DigitalOcean RDS Neon Railway Supabase Render Self-hosted

Why self-hosted

Your rows never visit my servers.

Data stays on the box

Snapshots write to disk you control, or your own S3-compatible bucket on Pro. No hosted proxy reading production.

If Tablebelt dies, production doesn't

It sits only in the agent's path. The app keeps the direct connection. Failure blocks the agent, not your users.

One binary, no extra fleet

A Go process you can systemd, docker, or just run.

Pricing

Simple pricing. Founding members lock it in.

Prices may change before launch. The founding rate will not.

Founding: £99/year for Pro on one database

£99/year vs £180/year at the ordinary Pro rate of £15/month. For people on this waitlist. Locked for the first year you pay. After that year it's ordinary Pro at £15 per database per month.

Free

£0 1 database

  • Local CLI approvals
  • Local snapshots
  • Destructive SQL held
  • Fail closed

Pro

£15 per database / month

  • Phone approvals
  • Undo history and retention
  • Snapshots to your own object storage

Team

£59 per month

  • Everything in Pro
  • Up to 10 databases, so less per database than Pro
  • Shared policy file
  • Multiple approvers
  • Audit export

FAQ

The questions I'd ask.

Where does my data go?

Your machine. Statements, snapshots and restore points stay there. I never host your Postgres.

How does it sit in the path?

A Postgres wire-protocol proxy. MCP, psql, or an ORM talking Postgres all connect to it. Client snippets ship with the binary.

What counts as destructive?

DROP TABLE / SCHEMA / DATABASE, TRUNCATE, DELETE / UPDATE without a WHERE, ALTER ... DROP, DISABLE ROW LEVEL SECURITY, and anything that can't be parsed. A shared policy file is on Team. Editing the list on Free or Pro is still open.

Does it actually parse SQL, or regex?

It parses. Unparsed SQL doesn't run. Which parser, and how I'll treat tautologies, CTEs, functions, DO blocks and prepared statements, are details coming.

What does restore restore?

The snapshotted tables, as they were at snapshot time. Later writes to those tables are lost. Not whole-database PITR, and it doesn't undo a cascade it didn't snapshot. DROP DATABASE needs a whole-database snapshot. Details coming.

Where do snapshots live?

Disk you control, or your own S3-compatible bucket on Pro. How the snapshot is taken, large-table time, and default retention are details coming.

Can the agent just bypass it?

Yes, if it can read the raw database URL. Give the agent only the Tablebelt string, keep the real URL off that machine, and use a Postgres role it can only reach through Tablebelt. Pair that with hooks that block .env reads if the agent supports them.

What about managed Postgres?

Planned wherever a Postgres connection works. Poolers, IAM auth and forced TLS are the usual wire-proxy breakages. I haven't proven those yet.

What's the latency?

A local in-process parse on the agent's network. I expect milliseconds. I'll publish numbers when they exist.

What if Tablebelt goes down?

The agent is blocked. Your app is not, because it never goes through Tablebelt.

How is this different from a read-only role, or my host's PITR?

Read-only means the agent can't fix anything. PITR rolls the whole database back. Tablebelt holds one statement, snapshots what it touches, and lets everything else carry on.

MySQL, or anything else?

Postgres only at first. If that's a deal-breaker, pick host: other on the form.

Will it be open source?

I plan to open source the classifier. Undo, phone approvals and retention are the product. Licence isn't decided.

When does it ship?

The plan is a free single-database CLI first. Early access goes to the waitlist first. I'll post progress on X. No date.

Founder

Why I'm building it

I'm Kyle Redelinghuys. I write Go, Vue and Postgres, run it all on DigitalOcean, and have Claude Code, Cursor or Codex open most days. My most-read post is on when --dangerously-skip-permissions is fine, and I built Vouch because an agent saying "done" isn't proof. Tablebelt is the same view: a CLAUDE.md rule is a suggestion, and the control that holds is in the call path. I'm building it for my own databases first. If your stack looks different, tell me on the form.

ksred.com · @ksredelinghuys

Waitlist

Get on the list before the next DROP.

Email is enough. Two quick questions after you join help me build the right first binary.

You're on the list. Tell the next person who posts a dropped-prod thread.

Share on X