When two callers ask the same question of the same database, the schema context sent to a text-to-SQL model can—and often should—differ if their permissions differ. The safer design is to apply authorization before schema retrieval, so a caller without access to a restricted table never puts that table’s details into the model’s context.
What changes when the caller changes?
The natural-language question and database may stay constant; the caller’s identity and authorized roles do not. A schema-selection step can use those permissions to decide which tables, columns, or other database objects the model is allowed to see while generating SQL.
As an Amazon Associate I earn from qualifying purchases.
In the example described by Ashish Sinha on DEV Community, a caller without the payroll role does not receive the hr_compensation schema in the model input. A caller with that role receives schema context that includes it. The article’s point is not that the question itself changes, but that the permitted context does.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
This is authorization-sensitive schema retrieval: first determine what the caller may access, then retrieve relevant schema information from within that permitted set. It differs from retrieving the most relevant schema objects first and checking permissions only after the model has already seen them.
#1 Best Overall
Why apply authorization before sending schema context?
Schema descriptions can reveal sensitive information even when no query results are returned. Table names, column names, and relationships may expose the existence or structure of payroll, health, or other restricted data. If such details reach the model, withholding them only at SQL execution time does not undo that disclosure.
- Filter the candidate schema by the caller’s permissions. Use the authenticated identity and role grants to establish the set of objects the caller may use.
- Retrieve relevant context from that allowed set. Rank or select objects for the question only after the authorization boundary is applied.
- Keep execution authorization in place. The database or a trusted execution layer must still enforce permissions on the generated query. Schema filtering is not a substitute for database access controls.
The DEV Community example also describes a claims schema in which objects requiring actuarial or phi access were withheld from a caller lacking those roles. Its excerpt reports demonstration counts, but those counts are article-reported examples rather than independently verified measurements.
What the retrieval figures do—and do not—show
The author reports top-10 gold-table inclusion of 82.6% for Spider pooled into a catalog of 876 tables, and 64.0% for Spider 2.0-lite across 247 usable questions. These are retrieval measurements reported by the author, not a guarantee that a different database, permission model, or workload will achieve the same results.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteThe article says its benchmark documentation describes the evaluation harness and two measurement errors corrected during evaluation. The exact dataset configuration, methodology, and corrections are not established in the available article excerpt. The figures therefore should not be treated as independently reproduced or used as a comparative ranking against other schema-retrieval systems.
Top-10 inclusion also answers a limited question: whether a gold table appeared within the first ten retrieved candidates. It does not by itself establish that generated SQL is correct, that unauthorized context is never exposed in every system component, or that retrieval is adequate for a particular production workload.
How to assess this design for a real application
- Define the authorization source. Identify which identity provider, database grants, or application roles determine access, and how changes to those grants reach the retrieval layer.
- Enforce permissions before retrieval. Ensure the retrieval index or query path cannot return restricted schema details to an unauthorized caller. A prompt telling the model to ignore an object is not equivalent to withholding that object from its context.
- Test both retrieval and isolation. Measure recall at a stated cutoff for authorized questions, and separately test that restricted object names and descriptions do not appear in unauthorized model inputs, logs, or downstream components.
- Validate generated SQL at execution time. Use database-enforced permissions or a trusted query layer; do not assume that correct schema filtering guarantees safe SQL.
- Evaluate with your own schemas and roles. Include questions whose answers require allowed objects, questions that mention restricted concepts, and users whose grants change. Benchmark results from another dataset do not settle those cases.
What is known about the referenced implementation?
The indexed excerpt attributes support for SQLite, PostgreSQL 16, Oracle 26ai, SQL Server 2022, and MySQL 8.4 to the article, and also lists an MCP server, a LangChain retriever, and a CLI. These are author claims; compatibility, licensing, and integration details are not independently established here. The same excerpt cautions that retrieval quality is limited, stating: “A selection step is only as good as its retrieval, and mine is not state of the art.”
Rank #4
A historical information-retrieval study used one database and the same written question for different searchers, while noting that these controls departed from real-life searching. That framing may help explain the controlled “same question, same database” comparison, but it does not validate a text-to-SQL system or its benchmark results.
Recommended Free Tools
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




