Skip to content
AI · Public sector

Natural-language reporting across a government data warehouse

Analysts ask a question in plain language; the system writes verified, read-only SQL against a governed warehouse and returns the answer with its workings.

Natural-language reporting across a government data warehouse
Client
State government department (under NDA)
Industry
Public sector
Timeline
4 months, fully on-premise
Platforms
Web · On-premise
Overview

A department with a large, well-governed warehouse and a small BI team: every routine question became a ticket, and answers took days. We built a text-to-SQL layer that lets non-technical staff self-serve — without letting a language model near production write access or sensitive data.

The challenge

The constraint was not generating SQL. It was doing so inside a public-sector environment where data cannot leave the premises, every query must be attributable, and a confidently wrong answer is worse than no answer at all.

  • Routine reporting requests took days to reach an analyst
  • No data, including prompts, could leave departmental infrastructure
  • Hallucinated columns or joins would silently produce plausible, wrong numbers
  • Every access had to be auditable and respect existing role permissions
Our approach

How we built it

  1. 01

    Ground the model in the real schema

    Table and column metadata, descriptions and verified example queries are indexed as embeddings, so the model retrieves the actual schema slice a question needs rather than guessing.

  2. 02

    Constrain generation, then verify

    Generated SQL is parsed and validated against an allow-list of tables and joins before execution — anything referencing an unknown column is rejected and retried, never run.

  3. 03

    Execute in a read-only sandbox

    Queries run through a read-only replica under the signed-in user's own role, so existing row-level permissions apply unchanged. Statement timeouts and row caps prevent runaway scans.

  4. 04

    Show the workings

    Every answer displays the SQL it ran, the tables touched and a confidence signal, so an analyst can verify before circulating a number. Everything is written to an immutable audit log.

  5. 05

    Keep it on-premise

    A self-hosted open-weight model, deployed on the department's own Kubernetes cluster, behind existing SSO. No prompt or result ever leaves the building.

What we shipped

In the delivered product

Plain-language question box with schema-aware autocomplete
Generated SQL shown alongside every result
Read-only execution under the user's own database role
Saved and scheduled questions for recurring reports
CSV and dashboard export
Full audit trail of question, SQL, user and result
The outcome

Results

Days → seconds
Turnaround on routine reports
~70%
Reduction in ad-hoc BI tickets
100%
Queries audited and permission-scoped
Zero
Data leaving departmental infrastructure
More work

Other projects

View all projects

Ready to build something people trust?

Book a free consultation. We'll map the highest-impact opportunity for your business — no obligation.