AI can now change measures and data models, not just query them. See how a governed semantic layer keeps AI-made analytics changes under control.

Asking an AI assistant to explain your revenue numbers is one thing.
Asking it to change how revenue is calculated is another.
Imagine Finance and Sales both rely on the same Monthly Sales measure. It feeds the CFO’s Excel workbook, the sales dashboard, and the answers people get when they ask AI about revenue.
An analyst spots a problem with the calculation and asks Claude to fix it.
Claude does.
Now what?
Does the change immediately become the new definition of Monthly Sales? Can you see exactly what changed? Can you undo it? What happens to everything downstream? And does any of this change if another team uses ChatGPT instead?
These weren’t particularly urgent questions when AI could only ask questions about analytics.
They become very real once AI can change the analytics underneath them.
Much of the conversation around AI governance in analytics has focused on what an assistant is allowed to see.
Can it access this row? Should that column be masked? Does this user have permission to query that data?
Those controls still matter. Semantic-layer platforms increasingly apply permissions and business definitions between the AI and the underlying data, rather than expecting the model itself to decide what it should access.
But AI assistants are starting to do more than query what somebody else has built.
Connect an assistant to Astrato through MCP and it can work with the semantic layer itself. Depending on the user's permissions, it can:
It works on the user's behalf and within the same permissions they already have.
That changes the risk.
One wrong answer can mislead one person. One wrong shared definition can affect everyone who uses it.
Change the definition of revenue, ARR or active customers and the consequences can travel much further than one AI conversation. The same definition may be feeding dashboards, spreadsheets and other analytics experiences.
So the question is no longer simply whether AI should be allowed to touch the model.
It’s what happens to an AI-made change before everyone else starts relying on it.
This is where the way the semantic layer handles change becomes important.
An edit doesn't have to become production simply because an AI assistant made it.
In Astrato, semantic-layer changes happen in a working copy. Changes are recorded in version history, known model issues can block publishing, and publishing determines when the new model reaches the workbooks and dashboards that depend on it.
In simplified form:
Go back to our Monthly Sales example.
You ask Claude to fix the measure. It can find the definition and make the change without you opening the Semantic Layer Editor and doing the work manually.
But the edit still enters the same change-management system as other semantic-layer work. It can be inspected in version history. If the model contains validation issues, publishing is blocked until they're resolved. And if the change turns out to be wrong, earlier versions can be compared and restored.
The AI gets to do useful work without getting a separate route around the controls already protecting the shared model.
That’s a much more useful boundary than “AI can read, but AI can never change anything.”
There’s another problem waiting behind AI adoption: different teams aren't necessarily going to choose the same assistant.
Your organization might eventually look something like this:
Trying to solve AI governance inside each interface creates a moving target.
The alternative is to keep the shared business context underneath them.
Astrato's MCP connection has already been tested with Claude, ChatGPT, VS Code, Claude Code, Snowflake CoCo and OpenAI Codex, with support for other MCP clients as well. Each connects to the semantic layer rather than maintaining its own independent definition of the business.
That means “Monthly Sales” doesn't have to become one thing in Claude and something slightly different in ChatGPT.
The measure lives in the semantic layer.
The assistant can change. The business context doesn't have to.
That's the more interesting version of bring-your-own-AI. You aren't simply adding more AI integrations. You're separating the place where people choose to work from the place where the business decides what its data means.
There are two easy answers to AI write access.
Keep AI read-only.
The assistant can identify the problem, but the analyst still has to leave the conversation, open another tool, find the definition and make the change manually.
Give AI unrestricted control.
Now you've removed the friction, but you've also removed the useful boundary between doing work and trusting that work.
Neither is particularly satisfying.
The better model is familiar because we already use it for people:
Let AI work inside the governed development process instead of creating a shortcut around it.
Astrato's semantic-layer workflow separates the working copy from what is currently live. Version history records changes. Validation prevents a model with known issues from being published. Publishing controls when the new definition reaches downstream consumers.
And if you explicitly ask a connected AI assistant to publish, it can do that too — subject to your permissions.
That's an important distinction.
Governance isn't necessarily about requiring a human to click every button. It's about making sure AI operates through the same controlled system rather than outside it.
The mechanics can protect quite a lot:
But none of that can decide what Monthly Sales should mean.
A measure can be technically valid and still be wrong for the business.
Maybe Finance defines revenue net of refunds while Sales has been using gross sales. Validation can check whether a formula is structurally sound. It can't settle that disagreement.
Astrato makes a similar distinction with its own AI-generated measure and dimension suggestions: a suggested formula may be reasonable based on the data, but only the business knows whether something like Gross Margin should include or exclude particular costs.
That's where people remain important.
The useful human role isn't necessarily making every edit manually.
It's owning the definitions and deciding what should become trusted business context.
MCP is what makes it practical for different AI assistants to work with external tools and context. But the protocol isn't the most important part of this change.
The bigger shift is what we're starting to ask AI to do.
The first wave of AI analytics was largely about making data easier to question. Ask in natural language, get an answer.
Now AI is moving further into the work itself: finding definitions, fixing measures, creating new ones and changing the model those answers depend on.
That demands a different kind of trust.
Not trust that AI will always be right.
Not trust that every employee will use the same AI assistant.
And not a governance model that assumes keeping AI read-only is the only safe option.
What you need is a system where AI can do meaningful analytics work without bypassing the controls that make that work trustworthy.
That's a much more interesting future than another chatbot sitting on top of a dashboard.
And we're already starting to build it.
See how Astrato runs natively in your warehouse.