EDB Agent Governance is a standalone application that provides observability and oversight for AI agents operating on Postgres databases. It lets database administrators, security teams, and AI operations engineers monitor, audit, and reason about how AI agents interact with enterprise data.
The application reads agent telemetry directly from a Postgres database running the aidb extension. aidb records every agent call, and the governance decision purpose enforcement made for it, inside the database; the application presents that telemetry as sessions — logical groupings of the steps an agent took in one interaction — with tools for filtering, inspecting, and auditing agent behavior. Postgres clusters managed by EDB Hybrid Manager (HM) and standalone Grafana Loki endpoints are also supported as a legacy source, in which the application reconstructs sessions from the Postgres query logs that agents generate through the Airman Model Context Protocol (MCP) server.
Exploring capabilities
Use EDB Agent Governance to:
- See each cluster at a glance — A dashboard per cluster counts agent activity and governance decisions and shows the most active agents.
- Reconstruct agent sessions — Step through what an agent did, with the SQL, timing, and, for
aidbdatabases, the governance decision behind each step. - Review governance decisions — For
aidbdatabases, see which agent actionsaidbapproved or denied, why, and on whose behalf. - Spot agents that keep getting denied — Review each registered agent's permissions and how often governance denied it, over the last 7 days or a date range you choose.
- Audit across databases — Connect several
aidbdatabases, and any legacy HM or Loki sources, and audit all of them from one place.
Getting started
Start with these pages:
- Key concepts — The key terms used throughout the application: instances, agents, purpose, governance decisions, sessions, and steps.
- Architecture and data flow — How the telemetry
aidbrecords reaches the application. - Installing — Deploy the Helm chart from EDB Repos 2.0 on Kubernetes.
- Configuring — For administrators configuring the application after deployment.
- Securing access and handling credentials — Authentication, credential storage, and how your data is treated.
- Connecting an aidb database — Prepare a Postgres database that runs the
aidbextension and register it so its agent telemetry and governance decisions appear. - Reading the cluster dashboard — Open a cluster and get an overview of its agent activity and decisions.
- Browsing activity — Find and filter the sessions, connections, conversations, and traces recorded for a cluster.
- Inspecting a session — Step through a single session, including the decision and SQL for each step.
- Reviewing agents — Review registered agents, their permissions, and how often governance denies them.
Using legacy sources: Hybrid Manager and Loki
Use the legacy sources if your AI agents reach Postgres through Airman MCP rather than running inside aidb. The application can still reconstruct their sessions from Postgres query logs stored in HM's Loki pipeline or a standalone Loki endpoint. This path shows the SQL each session ran, but it records no agent identities or governance decisions.
- Connecting Hybrid Manager or Loki — Register an HM or Loki instance so its agent sessions appear.
- Configuring Airman MCP — Set up Airman MCP instances with purpose labels, access modes, and PostgreSQL roles so governance boundaries are enforced.
- Governance in Hybrid Manager — The HM-specific integration details: Machine user API keys, HM's Loki pipeline, and project and cluster discovery.
Key concepts
Key terms used throughout EDB Agent Governance — instances, clusters, agents, purpose, governance decisions, sessions, and steps — and the terms specific to the legacy Hybrid Manager and Loki sources.
Architecture
How the AI agent activity that the aidb extension records reaches the EDB Agent Governance screens, and how the legacy Hybrid Manager and Loki path differs.
Installing
For administrators installing EDB Agent Governance — prerequisites, the container stack, installing the Helm chart, and the values you set.
Configuring
For administrators configuring EDB Agent Governance — managing identity providers and securing your deployment.
Securing access and handling credentials
How EDB Agent Governance authenticates users, connects to aidb, Hybrid Manager, and Loki sources, stores upstream credentials, and treats your data.
Connecting an aidb database
For database administrators preparing a Postgres database that runs the aidb extension so its AI agent telemetry appears in EDB Agent Governance — enabling telemetry, creating the viewer role, and registering the database as an instance.
Dashboard
Get an overview of AI agent activity and governance decisions for one cluster in EDB Agent Governance.
Browsing activity
Find and filter the AI agent sessions, connections, conversations, and traces recorded for a cluster in EDB Agent Governance.
Inspecting a session
Inspect a single AI agent session step by step, including the governance decision and SQL for each step, in EDB Agent Governance.
Reviewing agents
Review the AI agents registered in an aidb database, their permissions, and how often governance denies them, in EDB Agent Governance.
Connecting HM or Loki
Register an EDB Hybrid Manager or standalone Loki instance — the legacy, log-based sources — so the AI agent sessions reconstructed from their Postgres query logs appear in EDB Agent Governance.
Configuring Airman MCP
Set up Airman MCP instances with purpose labels and access modes, and configure Postgres roles so governance boundaries are enforced at the database execution boundary.