Databases
Create SQLite databases that Praxis hosts, attach them to your agents, and give each agent tools to store, query, and update structured data as it works.
A Praxis database is a SQL data store that your agents own and populate. You create one, attach it to one or more agents, and those agents can then define tables, write rows, and read the data back while they work. Each database is a SQLite database that Praxis hosts for you.
This is a database Praxis creates and hosts as a working store for your agents, not a connector to an existing external database. There is no host, port, or credential to enter, and a new database starts empty. Your agents put the data into it.
Create a database
Open Settings > Databases and select New database:
- Enter a Name. It uses lowercase letters, digits, and underscores only, and cannot be changed later.
- Optionally add a Display name for lists and a Description of what the database is for.
- Create the database.
It is ready right away, with no tables in it yet. The name identifies the database to your agents; the reason it is fixed is covered under attaching, below.
Attach a database to an agent
A database does nothing until an agent holds it. Attaching a database to an agent is what puts the tools to use it in that agent's hands. You attach from the agent's own settings, not from the Databases page: when you build or edit an agent, a Databases section lets you select the databases to attach. Attaching takes effect on the agent's next run, with no separate capability to switch on.
One database can be attached to many agents, and one agent can hold many databases. When an agent holds more than one, each database's tools are named after that database (for example, run_sql__customers) so the agent can address each one without ambiguity. That naming is why a database name is fixed and restricted at creation.
The Databases page reflects these attachments read-only: each database shows whether it is unattached or how many agents share it. You can also create and attach a database by asking an agent to do it in a chat.
Read and write data
Once a database is attached, the agent works with it from a chat. It creates the tables it needs (with a define_schema tool), then reads and writes rows as its task requires, seeing the current table definitions each time so it knows the shape of the data. Two tools back this:
- Read (
run_sql): runs read-only queries such asSELECTand returns rows. - Write (
execute_sql): inserts, updates, and deletes rows, and creates or changes tables.
Concurrent writes are safe. When two agents write at the same time, Praxis serializes the writes and retries automatically, so no update is silently lost; under heavy contention a writer may retry briefly before it succeeds. Each database shows a version that advances with every write.
Edit or delete a database
Use Edit to change a database's Display name or Description. Its tables and data are managed by agents from chat, not from this dialog.
Use Delete to remove a database. If any agents have it attached, deleting detaches it from all of them first.
Deleting a database is permanent. It removes the database and everything stored in it, and detaches it from every agent that used it. This cannot be undone.
What attaching a database allows
Attaching a database to an agent grants that agent full read and write access to everything in it. The read tool is genuinely read-only, but the write tool is unrestricted within the database: an agent can change or delete any row, and can create, alter, or drop any table. There is no per-table permission and no read-only mode for an attached agent. Attach a database only to the agents whose job needs it, and treat a shared database as writable by every agent attached to it.
Access is scoped two ways. Every database is visible only inside the organization that created it, so one organization's data never surfaces in another's session. Within your organization, an agent can reach only the databases explicitly attached to it. Attaching or detaching a database requires ownership of the agent, and an organization admin can also manage attachments.
Because there is no external system to reach, a database has no connection string or stored credential. Its contents live in storage Praxis manages, isolated per organization.
One boundary is worth stating plainly: these writes are not gated by human approval. In an unattended run, watching a Slack channel, running on a schedule, or investigating an incident, an attached agent can write to and delete from its databases without anyone approving each change. This differs from the cloud and Kubernetes tools, which stay read-only in every mode. For the full model, see How Praxis works and stays safe.
Related
- Build your own agent - Attach databases and set what an agent can reach
- Connect a Tool - Add MCP servers and custom Python tools to your agents
- How Praxis works and stays safe - The execution and safety model behind every agent