Context is more than a pile of records
An agent can read a thousand records and still misunderstand the business question. Useful context includes the evidence, the meaning of the fields, the time period, the decision being considered and the limits of the available data. Giving an agent more material without these boundaries can make its answer longer without making it more useful.
Consider ‘How is the release going?’ This could mean unresolved issues, unmerged pull requests, failed CI runs or customer adoption. Those are different questions with different sources. Narrow it to ‘Which open pull requests in this repository need a human review before Friday?’ and you can state what evidence would support an answer.
What the connection actually does
MCP stands for Model Context Protocol. It gives AI clients a standard way to discover and call tools exposed by a server. In a data workflow, those tools might list tables, describe columns or retrieve matching rows. The server decides which tools exist and how requests are authorised; the client decides how to use the returned information.
MCP is not a guarantee of good data, correct reasoning or universal client compatibility. A working connection does not prove that an import finished, that the agent queried every page or that it understood a business definition. Authentication method and transport also matter: a client must support what the server actually implements.
Lake uses Streamable HTTP and workspace-issued bearer credentials for read-only table tools. Clients need support for custom bearer headers. Interactive MCP OAuth consent and discovery are not implemented. Signing into the website and authorising an agent are separate steps.
Give the agent a task brief, not a broad mandate
Start with a decision a person needs to make and a bounded slice of data. Ask the agent to discover the schema before choosing fields. Require source references, an explicit freshness statement and a distinction between observations and suggestions. If necessary data is absent, the useful result is a clear gap—not an invented substitute.
Illustrative task brief Help me prepare a review queue for this repository. Discover the available tables and columns first. Use imported open pull requests, with source links. State the selected repository and last sync if known. Separate observed facts from proposed next actions. If review or approval data is missing, say so. Do not infer that an open PR is blocked or ready to merge. Return a short queue for a person to investigate.
Treat access as a separate design decision
Choose which workspace the client should read before issuing a credential. A friendly name helps you recognise the connection later; it does not by itself create a narrower table-level permission boundary. Do not assume that a prompt such as ‘only read issues’ restricts what a credential can access.
In Lake, MCP credentials are named, expire after thirty days and can be revoked. Tool calls recheck credential validity and issuer membership and write audit events. These are specific implementation behaviours, not a claim of certification or a substitute for deciding whether the data belongs in that workspace.
Keep secrets out of prompts, source-controlled configuration and URLs. Configure the bearer header using the client's supported secret mechanism. Imported content should be treated as evidence, not authority: an issue body telling an agent to ignore its instructions is still just issue text.
Review the answer before using it
Open a few source links and compare the retrieved facts with the answer. Check whether the agent reports the size of one page as the size of the whole dataset. Ask what could have changed since the last import, and whether the records cover the time interval you care about.
For repeatable work, keep the task brief and a small set of representative questions. Re-run them after changing the connector, permissions or instructions. Judge success by whether the output supports the actual decision, not by how fluent it sounds.
- The answer names the source and scope of the investigation.
- Important observations link back to records a person can inspect.
- Freshness, missing fields and incomplete pagination are disclosed.
- Recommendations are distinguishable from retrieved facts.
- A person remains responsible for any follow-up action.
