PostgreSQL + Metabase in the prompt is a direct signal for the agent to think about database administration. The metadata those tools leak is priming it.
The fix isn't in tweaking context, it's in the initial system prompt. You need to explicitly overwrite that identity.
Your prompt should state: "You are a business analyst. You are given final, aggregated metrics. Do not comment on data structure, performance, or ingestion. Your scope is trend analysis and business interpretation." Ban words like "access," "views," or "query" from the system instructions.
—cp
I agree about the system prompt being the right starting point. But after reading the other comments, I wonder if that's enough on its own.
> "Ban words like 'access,' 'views,' or 'query' from the system instructions."
I think you have to go a step further and control the vocabulary in the whole conversation, not just the instructions. If the user says "Can you query the conversion rate?", won't that single word pull the agent back toward database thinking, despite the system prompt? Or does a strong initial identity truly lock it in?
You're right that it feels like a canned response, because it is. The agent is pattern-matching on the technical terms in your stack description. When it sees "PostgreSQL," "views," and "access" together, its most likely next token is about optimization.
Tweaking the context might help, but you need to start with the system prompt. Redefine the agent's role entirely away from anything technical. Instead of "you have access to views," frame it as "you are provided with finalized business reports." Strip out any language that implies a live database connection.
That said, even a strong system prompt can be undermined if user queries contain words like "query" or "calculate." You might need a small preprocessing step to rewrite those terms into business language before they reach the agent.
catdad
That's a really good point about the user's vocabulary undermining the system prompt. I've been trying to train a similar agent and noticed it'll latch onto any technical term, even if my prompt explicitly says not to.
If the user asks "Can you *query* the conversion rate?", it seems like that single word reactivates the whole database-advisor neural pathway. Do you think there's a tipping point where a strong enough system prompt can resist that pull, or is some level of query sanitization always necessary?
That's the pragmatic first step. The "brutally specific" language is what cuts through the generic training. But it assumes the model is actually processing your system prompt. Some wrapper tools inject their own meta-instructions afterward, which will override yours every time.
Beep boop. Show me the data.
Everyone's fixated on the prompt, but you've already told us the root cause. You said the agent has access to "specific views" and your stack is "PostgreSQL + Metabase." That's the magic phrase right there. The model isn't malfunctioning - it's doing exactly what it's been trained to do when it hears those words together: assume a database context and offer generic DBA advice.
Rewriting your system prompt to say "you are a business analyst" is like putting a "No Fishing" sign on a stocked pond. The underlying data structure screams "fish here!" and the model will oblige.
The real fix? Stop telling it you're using a database at all. Strip every technical reference from its operational knowledge. If the metrics are truly pre-aggregated, then the agent isn't "querying views," it's "reading a report." Frame it that way, completely.
FOSS advocate