PTOLEMAOIS
Runtime Data Plane for LLM Workflows

Deterministic SQL Proxy & Schema Firewall for Autonomous Agents.

Autonomous agents generating unbounded queries are a FinOps hazard. Ptolemaois sits between LLM execution runtimes and your analytical data warehouse—parsing ASTs in <10ms, blocking unpartitioned full scans, and generating verified PySpark schema patches in-flight.

Request Production Pilot →
pip install ptolemaois-proxy
Intercept Latency
9.4ms (p99 AST parse)
Supported Warehouses
BigQuery, Snowflake, ClickHouse
Model Auto-Correction
Claude 3.5 Sonnet Engine
Lineage Standard
OpenLineage 1.2 / GCP PubSub
[01 // In-Line AST Inspection]

Intercepting Rogue Agent Queries

Proxy Rule: STRICT_PARTITION_ENFORCEMENT
ptolemaois-daemon :: listening on port 8443 (BigQuery proxy)
DRY-RUN AST FILTER ACTIVE
• INCOMING (Agent Generated) Scan: 8.4 TB (~$52.50)
-- Rogue agent query without partition bounds
SELECT 
  customer_id, 
  SUM(amount_usd) AS total_spend
FROM `raw_events.payments`
WHERE status = 'SETTLED'
GROUP BY 1 
ORDER BY 2 DESC;


[AST VALIDATOR REJECT]: Missing required clustering/temporal key `_PARTITIONDATE`.
Budget threshold exceeded: MaxAllowed=500MB, Estimated=8400GB.
• MODIFIED VIA CLAUDE ENGINE Scan: 42 MB ($0.0002)
-- Injected bounded temporal scope + cluster pushdown
SELECT 
  customer_id, 
  SUM(amount_usd) AS total_spend
FROM `raw_events.payments`
WHERE status = 'SETTLED'
  AND _PARTITIONDATE >= DATE_SUB(CURRENT_DATE(), INTERVAL 7 DAY)
  AND tenant_id = 'prod_eu_central'
GROUP BY 1 
ORDER BY 2 DESC;


[PROXY DISPATCH]: Validated with dryRun=true API.
Dispatched to BigQuery API backend. Latency overhead: 11.2ms.
[02 // Engineering Core]

Architecture & Operational Guarantees

MODULE // 01
Active AST Gateway

A zero-trust middleware that validates every Text-to-SQL statement against database metadata and AST token limits. Unpartitioned scans are dropped or rewritten before reaching storage billing APIs.

• Cost dryRun calculation via Warehouse APIs
• AST validation via SQLGlot & Rust bindings
• Per-tenant & per-agent credit ceilings
MODULE // 02
Self-Healing Pipeline Patch

Schema changes in upstream JSON APIs break downstream ETL. Ptolemaois catches PySpark and Dataflow stack traces, segregates drifted rows to dead-letter storage, and synthesizes schema-migration PRs.

• Java / Python stack trace root-cause parser
• Dead-letter quarantine without pipeline halt
• Claude 3.5 Sonnet code-patch generator
MODULE // 03
Streaming DAG Provenance

Connects every LLM prompt and tool invocation directly to analytical warehouse rows and vector retrieval snapshots. Full audit trails for regulated sectors (EU AI Act, HIPAA).

• OpenLineage 1.2 compatible DAG models
• Pub/Sub asynchronous metadata streaming
• Exact row-level hallucination debugger
[03 // Integration]

Two Lines in Python

Supports LangChain, LlamaIndex, DSPy & Raw Clients
# Minimal integration with LangChain / Custom Agent Runtime
import os
from ptolemaois import PtolemaoisGateway, BudgetPolicy

# Wrap your BigQuery or Snowflake client with deterministic guardrails
gateway = PtolemaoisGateway(
    api_key=os.getenv("PTOLEMAOIS_API_KEY"),
    warehouse="bigquery",
    policy=BudgetPolicy(
        max_bytes_per_query=500_000_000, # 500 MB ceiling
        require_partition_filters=True,
        auto_rewrite_with_sonnet=True
    )
)

# Autonomous Agent passes generated SQL string:
safe_query = gateway.intercept(agent_sql)
results = safe_query.execute()  # Executes safely within budget boundaries
[Pilot Deployment]

Protect Your Production Data Warehouses

Currently deploying private pilots with engineering teams running autonomous data agents in production on GCP and Snowflake.

Ptolemaois Inc. • Istanbul • Early Access 2026