A natural-language business assistant that only answers from executed SQL query results against a real (synthetic) database — never from model recall.
Business users want plain-language answers ("what were total expenses last month?") without writing SQL — but a general-purpose chatbot layered over company data risks answering confidently from the model's training data instead of the company's actual numbers.
A wrong number stated confidently is worse than no answer. If a chatbot will answer a general-knowledge question once from memory, a user has no way to know when it's answering from real data versus guessing.
An agent with exactly one capability: run SQL against a synthetic company database. A system prompt enforces that every factual answer must come from an executed query, cites the source table, and returns a fixed, verifiable refusal message when a question falls outside the schema.
User question
-> Agent + BusinessAssistantSystemPromptBuilder
- enforces: answer ONLY from SQL results
- enforces: exact fallback message for out-of-schema questions
- enforces: cite source table(s) in every answer
-> llama3.1:8b (local) decides whether/what SQL to run
-> RunSqlTool -> SqliteRunner -> company.db (8 synthetic tables)
-> real query result -> model states the answer + source table(s)
Real output from a live run against local Ollama:
Q: How many contracts expire within 90 days? A: The number of contracts that expire within 90 days is 4. (contracts) Q: What is the capital of France? A: I don't have enough information in the connected dataset to answer that.
SQL generation as the hallucination guard. Not a prompt suggestion layered on a free-form chatbot — the agent structurally cannot answer a factual question without first producing an inspectable query.
Built on an archived library, kept alive. The upstream framework (vanna-ai/vanna) was archived by its maintainer in March 2026; this project vendors it and continues building on it independently rather than treating "archived" as a dead end.
No API keys — the LLM runs entirely locally via Ollama. The agent's only tool is read-only SQL execution; there is no write/delete capability exposed.