Multi-tenant LLM analytics with row-level security: How we built a secure agent on AWS
PAR built a multi-tenant text-to-SQL analytics agent on AWS enforcing row-level security via a three-layer architecture.
“A model that correctly applies a business ID filter ten thousand times in a row may silently omit it on the ten thousand and first.”
PAR Technology detailed how it built a production text-to-SQL agent on AWS that enforces tenant data isolation through cryptographic request signing, semantic validation on Bedrock, and Split-Plane SQL rather than trusting the LLM. The piece matters as a concrete engineering pattern for securing non-deterministic LLMs in multi-tenant systems, but it is a vendor case study with limited broad industry signal.