Read-only MCP
Safe, until the agent needs to fix what it just diagnosed, and you're pasting SQL by hand.
In development, waitlist open
A self-hosted Go proxy between your coding agent and Postgres. It'll hold DROP, TRUNCATE and unscoped writes for your approval, snapshot the affected tables first, and restore them with one command. Not built yet, I'm writing it now.
One email when early access opens. No drip sequence.
You're on the list. Tell the next person who posts a dropped-prod thread.
Share on XThe problem
Then it decided the users table looked like leftover test data. Same cause every time: the agent had the real credentials, and the only guardrail was text in a prompt.
Why now: this is already happening in public. Replit's agent deleted a company's production database in July 2025, and a Cursor agent wiped a startup database in April 2026. I'll post progress on X.
Safe, until the agent needs to fix what it just diagnosed, and you're pasting SQL by hand.
Suggestions. The model ignores them the moment a cleanup looks obvious.
Last night's dump, a restore you've never run, and every write since midnight gone.
How it works
The agent gets a Tablebelt connection string and the app keeps the real one, so Tablebelt is never between your users and the database.
# Point the agent at Tablebelt, not Postgres
DATABASE_URL=postgres://agent@127.0.0.1:5439/app
# App keeps the real URL, off the agent host
# postgres://app@db.internal:5432/app
DROP TABLE users; hits Tablebelt, not Postgres. Same for TRUNCATE, unscoped DELETE, and ALTER that drops a column.
If the statement is destructive, or it can't be parsed, it doesn't run. The agent gets a structured error it can explain back to you.
You get a ping with the exact statement. Approve and Tablebelt snapshots the affected tables, then runs it. Deny and the agent is told no. Free approves in a local CLI.
tablebelt restore snap_id puts those tables back as they were at snapshot time. It's not point-in-time recovery for the whole database. Writes after the snapshot are lost.
$ tablebelt restore snap_0001
restoring public.users from snap_0001
ok public.users
note writes after snapshot are gone
What it catches
Parser-based, not a denylist of string prefixes. If Tablebelt can't read it, it doesn't run it. The exact parser is still coming.
DROP TABLE / SCHEMA / DATABASE
Gone, and no migration file brings the rows back.
TRUNCATE
Every row in one statement, with no WHERE to scope it.
DELETE / UPDATE
Held when there's no WHERE. Scoped writes can still go through. I haven't decided yet how to treat WHERE 1=1 or other tautologies.
ALTER ... DROP
Columns and tables you can't get back from a migration file the agent also rewrote.
DISABLE ROW LEVEL SECURITY
Nothing is deleted, but every row is suddenly readable by whoever has a key.
unparsed SQL
If it can't be parsed it doesn't run, because production isn't the place for a best-effort guess.
Works with
It works over the Postgres wire protocol, so it doesn't care who hosts the database.
Planned support
Agents
Postgres hosts
Why self-hosted
Snapshots write to disk you control, or your own S3-compatible bucket on Pro. No hosted proxy reading production.
It sits only in the agent's path. The app keeps the direct connection. Failure blocks the agent, not your users.
A Go process you can systemd, docker, or just run.
Pricing
Prices may change before launch. The founding rate will not.
£99/year vs £180/year at the ordinary Pro rate of £15/month. For people on this waitlist. Locked for the first year you pay. After that year it's ordinary Pro at £15 per database per month.
£0 1 database
£15 per database / month
£59 per month
FAQ
Your machine. Statements, snapshots and restore points stay there. I never host your Postgres.
A Postgres wire-protocol proxy. MCP, psql, or an ORM talking Postgres all connect to it. Client snippets ship with the binary.
DROP TABLE / SCHEMA / DATABASE, TRUNCATE, DELETE / UPDATE without a WHERE, ALTER ... DROP, DISABLE ROW LEVEL SECURITY, and anything that can't be parsed. A shared policy file is on Team. Editing the list on Free or Pro is still open.
It parses. Unparsed SQL doesn't run. Which parser, and how I'll treat tautologies, CTEs, functions, DO blocks and prepared statements, are details coming.
The snapshotted tables, as they were at snapshot time. Later writes to those tables are lost. Not whole-database PITR, and it doesn't undo a cascade it didn't snapshot. DROP DATABASE needs a whole-database snapshot. Details coming.
Disk you control, or your own S3-compatible bucket on Pro. How the snapshot is taken, large-table time, and default retention are details coming.
Yes, if it can read the raw database URL. Give the agent only the Tablebelt string, keep the real URL off that machine, and use a Postgres role it can only reach through Tablebelt. Pair that with hooks that block .env reads if the agent supports them.
Planned wherever a Postgres connection works. Poolers, IAM auth and forced TLS are the usual wire-proxy breakages. I haven't proven those yet.
A local in-process parse on the agent's network. I expect milliseconds. I'll publish numbers when they exist.
The agent is blocked. Your app is not, because it never goes through Tablebelt.
Read-only means the agent can't fix anything. PITR rolls the whole database back. Tablebelt holds one statement, snapshots what it touches, and lets everything else carry on.
Postgres only at first. If that's a deal-breaker, pick host: other on the form.
I plan to open source the classifier. Undo, phone approvals and retention are the product. Licence isn't decided.
The plan is a free single-database CLI first. Early access goes to the waitlist first. I'll post progress on X. No date.
Founder
I'm Kyle Redelinghuys. I write Go, Vue and Postgres, run it all on DigitalOcean, and have Claude Code, Cursor or Codex open most days. My most-read post is on when --dangerously-skip-permissions is fine, and I built Vouch because an agent saying "done" isn't proof. Tablebelt is the same view: a CLAUDE.md rule is a suggestion, and the control that holds is in the call path. I'm building it for my own databases first. If your stack looks different, tell me on the form.
Waitlist
Email is enough. Two quick questions after you join help me build the right first binary.
You're on the list. Tell the next person who posts a dropped-prod thread.
Share on X