The context layer that checks itself · MCP-delivered

The context layer your AI data agent recalls mid-task.

Connect ClariLayer to Claude Code, Cursor, or Codex with a context key — or to claude.ai as an OAuth custom Connector. Bootstrap the context you already have, recall it in-flow, and check warehouse or HubSpot definitions without handing ClariLayer either system's credentials.

Connect your AI
ClariLayer — where it fits in your data stackClaude Code, Cursor, and Codex connect to ClariLayer over MCP with a context key; claude.ai connects as an OAuth custom Connector. In the personal MCP reconciliation path, the client queries a warehouse, dbt, or HubSpot with its own authorized access and sends supported evidence to ClariLayer. ClariLayer does not hold source credentials or connect to the live source on that path. It runs bootstrap, recall, remember and reconcile, and surfaces Diff to Canon when saved and canonical context differ. You get a grounded agent, a Context Console, and an Inbox with Activity and Replay. It runs on Supabase Postgres with row-level security. Status is caveat or asserted, never verified. The separate gated Governed Context Edge team-connector surface is outside this diagram and uses its own controls.ClariLayerwhere it fits in your data stackcontext · MCP, in-flowdata · your agent's source accesslocal agents / claude.aiMCPcontext key / OAuthSQL / CRMYour AI agentClaudeCursorCodexWarehouse, dbt, or HubSpotyour client's own source access —personal path: no direct connectionClariLayeryour context layerbootstraprecallrememberreconcileDiff to Canonyours · active_user = last 28 dayscanon · active_user = last 7 days⚠ differs — flagged on recallstatus: caveat or asserted · never “verified”Your agent, groundedstops repeating mistakeswrong table · join · refundsContext Consolesee + manage your contextstatus · provenance · where-usedInbox · Activity · Replayapprove proposalswatch the recall loopSupabase Postgres + row-level security · MCP (context key or OAuth) · served-trace storepersonal path shown · gated team connectors use separate controls
In the personal MCP path, your agent keeps its own warehouse and CRM access. ClariLayer never holds those credentials, runs SQL server-side, or calls HubSpot.

Four everyday verbs, in your agent

One MCP server. A durable context loop.

ClariLayer installs as an MCP server into the agent you already use. These four verbs are the everyday loop; supporting shipped tools handle review, lifecycle, full fetches, and task completion.

bootstrap

Bootstrap — don't blank-slate

Start from five shipped sources: SQL, dbt models, CLAUDE.md or freeform notes, a data dictionary, and a semantic model. SQL is deterministically structured; dictionaries become one schema note per variable; semantic models become canonical definitions; dbt and notes come along too.

recall

Recall — context in-flow

Recall pulls relevant context mid-task with provenance and status attached. Exact named entries lead, use-case scoping stays explicit, and honest-routing output says when useful context was scoped away instead of silently hiding it.

remember

Remember — so you stop repeating yourself

Every correction, join path, and gotcha you save is remembered across sessions. Your agent grounds on more of your context over time, so it gets progressively more right about your data. Want to capture a lot at once? Ask it to harvest the durable facts from a working session — they land in your Inbox for you to approve, never auto-saved.

reconcile

Reconcile — checked, not blindly asserted

Reconcile grounds a saved definition against one of two shipped evidence paths: a warehouse result shape, or bounded, row-free HubSpot property metadata and distributions. A mismatch becomes a caveat; otherwise the entry remains asserted.

Beyond the core loop

The trust loop keeps going after recall.

CRM evidence, an explicit completion checkpoint, and an inspectable Console make the surrounding context decision visible without pretending every check is a verification stamp.

HubSpot CRM

Property contracts, checked without CRM rows

Store expected internal values, canonical values, deprecated aliases, and labels. Your agent reads HubSpot with its own access and sends bounded metadata and distributions; in the personal MCP path, ClariLayer receives no CRM credentials or records and never calls HubSpot.

Completion receipt

Close the context loop before the task closes

Managed instructions guide a supported local agent through recall, confirmed context maintenance, and context_checkpoint. The durable, idempotent receipt persists the agent's context_updated or no_update_required declaration and validates ownership and eligibility of referenced ClariLayer objects; it does not independently prove an entry changed or certify code, query correctness, deployment, or an external system. Proposal-only work and update_failed cannot complete the loop.

Context Console

See what the agent saw — and where context disagrees

Review proposals, inspect the recall activity and Replay graph, compare local definitions with imported canon, label conflicts, record an adjudication, and capture corrections. The Console makes the trust loop inspectable without turning it into approval ceremony.

For HubSpot, an exact zero in a complete distribution means the value is absent from observed records; it does not mean the option is missing from HubSpot configuration.

Reconciled, not blindly asserted

The difference between a CLAUDE.md and context you can trust.

A hand-typed file of claimed definitions has the same trust problem as the original numbers — it's just asserted text. ClariLayer can reconcile a saved definition through two shipped evidence paths. For warehouse context, your agent reports a result shape from SQL it ran. For HubSpot property contracts, it reports bounded property metadata and row-free distributions. ClariLayer compares the declared contract with that evidence and flags a mismatch as a caveat.

In this personal MCP path, your agent remains the connector. ClariLayer never holds warehouse or CRM credentials, executes SQL server-side, or calls HubSpot. Warehouse evidence may contain preview rows if the agent chooses to send them; HubSpot evidence never contains CRM rows. Public reconcile uses two honest statuses: a mismatch becomes caveat, otherwise the entry remains asserted. Verified is not a live status.

asserted

Saved and not contradicted — the default for anything you remember. After reconcile, applicable checks may pass or be inconclusive and the entry still remains asserted; a mismatch becomes a caveat.

caveat

Reconcile caught a declared-vs-actual mismatch. The valuable signal: you and your agent now know exactly what to treat with care.

provenance

Every entry shows where it came from — you, SQL, a dictionary, dbt, a semantic model, or an agent proposal — next to its status so trust stays legible.

in-flow

The working loop rides inside the agent you already use, over MCP. The Console is there when you want to inspect it, not as a required destination.

In-flow, via MCP

One command — or one OAuth approval.

Connect Claude Code, Cursor, or Codex with a context key, or add ClariLayer to claude.ai as an OAuth custom Connector with no context key. From then on your agent can recall relevant context mid-task, remember confirmed corrections, and reconcile warehouse or HubSpot definitions without leaving the flow. The AI agent context guide walks through the managed recall-first loop for supported local agents, including the completion checkpoint.

The longer you use it, the more grounded it gets on your data — and the more annoying it would be to lose. The context you build is yours; it travels across your agents and later merges into shared team context. Already run a metrics stack? See how ClariLayer sits above your semantic layer.

Read the Quickstart — connect your AI
Connect over MCP
  1. 01

    Connect Claude Code, Cursor, or Codex with a context key — or approve the claude.ai custom Connector over OAuth.

  2. 02

    For a supported local agent, install the managed instructions that guide recall, confirmed updates, and completion checkpoints.

  3. 03

    Bootstrap from SQL, dbt, CLAUDE.md or notes, a dictionary, or a semantic model.

  4. 04

    After a confirmed live update — or a reviewed no-update decision — persist the agent's bounded completion declaration.

A session, before and after

What the core loop looks like on a real Tuesday.

Say you're an analyst chasing a familiar gap: the revenue dashboard says one number, the ad-hoc query you just ran says another, and the board deck is due this afternoon. Here is the same task without ClariLayer, then with it — using only the shipped loop, nothing roadmap.

Without a context layer

  • You open a fresh chat and re-type the basics: which table is canonical, which join is the right one, that refunds shouldn't count in net revenue. Again.
  • The agent confidently writes SQL against orders — but your canonical revenue lives in fct_orders, and it's counting gross, refunds included.
  • You catch it, fix it, ship the right number — and next session the agent makes the exact same mistake, because nothing about today was retained.

With ClariLayer, in-flow

  1. bootstrap — on day one you point it at ./analytics/sql and your dbt models, so the canonical revenue definition is already in your context store, structured into tables, joins, and time grain.
  2. recall — the agent pulls that definition mid-task and reaches for fct_orders from the start, with provenance and status attached so you can see where it came from.
  3. reconcile — you ask it to check the saved definition against the warehouse. It runs the SQL with its own access and reports the result shape back; reconcile compares that against the definition's declared signals — columns, grouping, aggregates — and the shapes don't match, so it records a caveat. That caveat is the flag to investigate, and it sends the agent back to the numbers, where it finds refunds are still in the total.
  4. remember — you save the correction once: net revenue must net refunds. Next Tuesday it's already there; the agent doesn't re-litigate refunds, and the context you built quietly compounds.
  5. context_checkpoint — before completion, the agent declares context_updated and references the active ClariLayer entry. If a review finds that nothing durable changed, it declares no_update_required instead. The checkpoint persists that declaration and validates eligible references; it does not independently prove an entry changed.

That caveat is the working output of the loop: reconcile records a caveat on a declared-vs-actual mismatch, or leaves the entry asserted when nothing conflicts. Throughout this personal MCP flow, ClariLayer never holds your warehouse credentials or executes SQL server-side: your agent is the connector, sending result metadata and any preview rows it chooses to include. The completion receipt persists the agent's bounded declaration; it does not independently prove a context entry changed or certify the SQL, code, deployment, or external system.

For teams · the Governed Context Edge · private pilot

Yours today. Your team's tomorrow.

ClariLayer starts as your personal context layer. The Governed Context Edge — the shared, governed team canon your personal layers connect into — is built and in a private pilot with a few design-partner teams.

Everything you build solo is what your team inherits: the Governed Context Edge promotes your reconciled definitions into a governed, shared canon. Early access is open now.

Governed metric definitions

As a team adopts ClariLayer, the personal context analysts build can be proposed up to shared, owned, governed context — tier-based approvals, immutable release bundles, and audit trails for high-stakes metrics.

Explore team governance, ownership, and release evidence

A governed edge between layers

Your reconciled definition can be proposed up to the team's shared layer, and the team's canon can flow back down to you — always with agency: adopt it, override it, or fork it, never a silent overwrite.

Explore how personal context becomes team canon

Validation that crosses the edge

What flows across an edge carries its owner, version, and validation evidence, so whoever adopts it — a teammate, or their AI data agent reading the governed contract — knows whether to trust it.

Explore the evidence a definition carries

The governed Contract API

As teams adopt it, agents, dashboards, and internal apps can fetch the governed definition, owner, version, and trust state through a read-only contract instead of scraping stale warehouse artifacts.

Explore the read-only contract for team agents and BI tools

Stop re-explaining your data to your AI.

Connect ClariLayer to Claude Code, Cursor, or Codex. It bootstraps your real working context from the SQL you already have, then your agent stops making the same data mistakes — session after session.

Connect your AI