# Data flow and privacy (https://docs.getaviato.com/administration/data-flow)



The database agent is the component that connects to your database. The control plane manages accounts, permissions, configuration, approvals, and audit services.

| Flow                     | Data involved                                                                                                                       |
| ------------------------ | ----------------------------------------------------------------------------------------------------------------------------------- |
| Agent to browser         | Records and fields the signed-in user may read.                                                                                     |
| Agent to MCP client      | Records the connecting user may read; the client may send them to its model provider.                                               |
| Agent to control plane   | Schema names and types, configuration exchanges, health and backlog metadata.                                                       |
| Agent to audit ingestion | Actor and operation metadata, identifiers, and field changes according to redaction settings.                                       |
| Agent to SDK plugin      | The requested operation and its context, at your configured plugin URL.                                                             |
| Record notes             | Note text is stored in the control plane. It checks record access with a fresh agent session and discards the returned record body. |

## Optional AI features [#optional-ai-features]

**Ask your data** sends your question and schema to the configured language-model provider to produce a query. It does not need to send record values for query generation, but any values you include in the question are part of the prompt.

**Decision fields** send their selected input fields for evaluation. **Risk checks** can send action information, target information, and form values. The configured provider may be reached through the control plane. A self-hosted decision endpoint changes that route.

Platform-funded requests have durable request quotas and concurrency limits. These credits are admission limits, not a promise of a particular currency cost.

## Approvals and hosted connections [#approvals-and-hosted-connections]

Approval targets and form values are sent to the control plane; form values are encrypted at rest. A hosted agent also requires its database connection details to be managed by the hosting platform. A self-hosted agent keeps its database credentials in your deployment.

## Audit values and destinations [#audit-values-and-destinations]

Full audit redaction mode can include business field values. Select a more restrictive mode if those values should remain out of the audit store. Audit exports and streaming send the resulting redacted events to your configured destination.
