How Aviato fits together
A shared vocabulary for workspaces, projects, environments, agents, and collections.
| Concept | What it means |
|---|---|
| Workspace | Your team, membership, subscription, and shared administration. |
| Project | One connected application and its configuration. |
| Environment | An isolated connection within a project, such as production or staging. |
| Database agent | The service that runs next to your database and enforces data access. |
| Collection | A database table, MongoDB collection, or custom collection exposed by a plugin. |
| Record | An item in a collection, identified by its primary key. |
| Action | A named operation defined by your development team. |
| Plugin | Your application code extending the agent through a language SDK. |
| MCP client | An AI application connecting to the agent through Model Context Protocol. |
The agent and the control plane
The database agent connects to your data sources. Your browser and authorized MCP clients request records from that agent. It applies permissions, runs operations, and queues audit events.
The control plane manages sign-in, workspaces, roles, agent configuration, approvals, and audit services. It does not connect directly to a self-hosted database. Some features send selected data through the control plane; see data flow.
Two kinds of agent
Aviato's database agent is infrastructure you deploy. An AI agent is a client, such as an assistant using MCP, which sends requests to it. Connecting an AI agent does not grant unrestricted database access.
Environments are separate
A record ID is only meaningful within its collection and environment. A customer numbered 42 in staging is not the same record as customer 42 in production. Check the environment selector before editing, running actions, or reviewing an approval.
Permissions follow the request
Workspace roles provide baseline access. Custom project roles can narrow it. MCP scopes further constrain what an AI client can do. A plugin using the agent's Data API operates under the caller's permissions.
From a collection to an audited change
The record guide walks through a real connected Customers collection. A teammate opens a row, saves an edit through the agent, and checks the resulting event in record activity and the audit log. The screenshots use a disposable database with fictional example data.