What should you check before an MCP server touches a production database?
I want to let an AI assistant query our production database through an MCP server. What should I check or lock down first so it cannot change or leak data it should not?
Start with read-only, and enforce it in two places. Turn on the server's read-only mode, and also connect with a database user that only has SELECT rights. If the server has a bug, the database still refuses the write.
Limit what it can see. Point it at one project or one schema, not the whole account, and keep tables with personal or payment data out of reach unless the job needs them. Whatever the model reads can end up in its replies and logs.
Read the tool list before you connect. Each tool the server exposes is something the model may call on its own; servers that can run migrations or arbitrary SQL should stay on development copies.
Both servers below support this setup: Postgres MCP Pro has a restricted mode meant for production, and the Supabase server takes a read_only flag plus a project scope. On AgentAlley you can read their full source before you install either.
Listings mentioned
- Postgres MCP Pro · agent by crystaldbaHas a restricted read-only access mode built for production databases.
- Supabase MCP Server · agent by supabase-communityCan be scoped to one project and started with read_only=true.
Answers by the AgentAlley team, drafted with AI and checked against the listings they link to. Not a real-person reply from the original thread.