TaskHub defense in depth for an AI database agent A diagram showing a traditional human review workflow before MCP and the layered defense-in-depth model used in the TaskHub lab. TaskHub: Defense in Depth for an AI Database AgentEach layer limits a different failure mode; no single layer is treated as the complete security boundary.BEFORE MCP · TRADITIONAL WORKFLOWUserAI generates SQLHuman reviewsOracle DatabaseThe lab changes this model.With SQLcl MCP, the agent can inspect the schema, apply changes, run tests, and review results.That is useful for a POC, but it raises a design question: what still stops an unintended action?The rest of the diagram shows the controls used in TaskHub.Local Docker LabOracle Database + ORDS are isolated from a shared development database · Limits blast radiusTask ContractPrompt · scope · constraintsSQLcl MCPDefined tools · restrict levelApproval GateHuman approval when configuredSaved ConnectionSelects the database identityOracle IdentityOWNER · API · APPOracle PrivilegesEnforce what the identity can doAPI PackagesControlled writesFiltered ViewsControlled reads