Hosted or self-managed/dbt-core 1.12/MetricFlow 0.15

The control plane for dbt Core.

Studio, orchestration, lineage, catalog and a MetricFlow semantic layer for your analytics engineering team, running against your own warehouse. Self-managed deployments run entirely on infrastructure you control.

Start your 30-day trialSee the platform

No credit card. Nothing charges when the trial ends.

Studio · fct_orders.sql
Forewarden Studio with fct_orders.sql open: the model's SQL and a query-results panel with 44 rows

FIG 1·Screens captured from the running product, shown at 1:1.

§ 01/How it fits together

dbt Core does the work. Forewarden runs everything around it.

The same models, tests, ref() and Jinja your project already uses, built by dbt-core itself in Forewarden's worker. Forewarden adds the editor, the scheduler, the record of every run, the catalog and the metrics layer, and keeps warehouse credentials encrypted and out of the browser. On a self-managed deployment the whole stack below runs on your own infrastructure.

Notes

1.

Develop

A real editor with compile, preview, lint and build against the environment you have open. Source control built in.

2.

Deploy

Environments pin a connection, schema and dbt engine. Cron jobs, chaining, retries, and CI and merge jobs that start when you push from Forewarden's Git panel.

3.

Explore

Lineage with full selector syntax, a searchable catalog with health and performance, and MetricFlow metrics.

4.

Investigate

An optional AI Data Engineer that answers questions about the project with read-only tools, inside your own role, and keeps its evidence apart from its conclusions. Off by default.

5.

Migrate

Turn existing Postgres tables and views into a dbt project on a new branch, verified by a build and row-level parity. Databricks import is in preview.

6.

Integrate

REST API with scoped tokens, an MCP server, SCIM 2.0 provisioning, and notifications by email, Slack, Teams or HMAC-signed webhooks.

§ 02/Beyond dbt Core

Why it goes further than dbt Core alone

dbt Core compiles and runs your models. Everything around that is left to each team to build. Forewarden does not replace dbt Core: its worker installs dbt Core 1.12 and runs it on your project unchanged, and Forewarden provides the rest.

Scheduling
dbt Core has no scheduler. Forewarden runs deploy jobs on cron (shown in plain English), after another job or on demand, with retries, timeouts and a node-by-node record of every run.
CI with deferral
dbt Core gives you state and defer flags to wire into a CI system yourself. Forewarden's CI jobs build state:modified+ into a per-branch schema, defer to production, and compare the result with production.
Lineage & catalog
dbt Core generates a static docs site. Forewarden keeps a live DAG with dbt selector syntax and a searchable catalog with health, performance, profiling and column-level lineage.
Governed metrics
dbt Core leaves MetricFlow to a command line. Forewarden validates the semantic manifest against the warehouse and gives you an explorer with chart, table, SQL and CSV.
Access control
With dbt Core, whoever holds the profile can run anything. Forewarden has five project roles, and running against production takes Maintainer.
Audit
dbt Core logs to whichever machine ran it. Forewarden keeps an append-only audit log and the history of every run and invocation.
Secrets
dbt Core reads credentials from profiles.yml or environment variables on each machine. Forewarden stores them encrypted with AES-256-GCM, decrypts warehouse credentials only in the worker, and runs dbt with an allowlisted environment.
AI investigation
dbt Core has none. Forewarden offers an optional, read-only AI Data Engineer and an MCP server, both limited to the caller's role and both audited.

§ 03/Studio

An editor that compiles ref() and Jinja against the environment you have open

Open a model, compile it, preview rows and lint it, with results, compiled SQL, problems and lineage in one panel. Run dbt from a command bar that accepts 16 dbt commands with checked flags. Every invocation is kept in history.

  • Multi-file tabs and drafts that survive a refresh
  • Defer to production so unchanged parents are not rebuilt, once production has a manifest
  • Diff, stage, commit, branch, pull and push, to origin and to every extra remote set to receive commits
Studio · dim_customers.sql · Compiled
Studio with dim_customers.sql open: ref('stg_customers') in the editor, and the Compiled tab below showing it resolved to the Production relation

FIG 2·Compile resolves every ref() and macro against the environment you have open.

§ 04/Orchestration

A record of every run, node by node

Deploy jobs run on cron, after another job, or on demand. CI jobs build only what changed when a branch is pushed from Forewarden's Git panel, and post a GitHub commit status when the project has a github.com remote with an access token. Logs stream live; each node keeps its compiled SQL, rows affected and a duration trend.

  • One production run at a time per project; development runs queue per user
  • A newer push to the same branch cancels the CI run it replaces
  • Isolated checkout of the pinned commit for every job run
  • Cancel, retry, timeouts, and a downloadable log for every run
Run history · dbt build
A successful dbt build in the Production environment: 29 nodes passed and 1 no-op, each with status, duration, rows and a trend sparkline

§ 05/Lineage & catalog

Lineage · fct_orders
Forewarden lineage graph with fct_orders selected, highlighting its upstream staging models and seeds and its downstream mart and exposure

FIG 3·The DAG from the latest successful production run's manifest.

Trace any model back to its sources and forward to what depends on it

The graph understands dbt's own selector syntax and set operators. The catalog carries columns, tests, profiling, contracts, access and version badges, with health, performance and 24 recommendation rules per project. Column-level lineage and full-text search, ⌘K from anywhere.

§ 06/Semantic layer

Define a metric once, then query it the same way from the explorer or an MCP client

Validate the semantic manifest against the warehouse, browse simple, ratio, cumulative and derived metrics with their dimensions, then explore them by time grain and dimension with a chart, a table, the generated SQL, and CSV export. Available on 7 of the 13 warehouses; there is no BI tool connector.

Semantic layer · Explore
Forewarden metric explorer charting completed_order_total by month against the Production warehouse

§ 07/AI Data Engineer

An AI data engineer that shows its evidence

The AI Data Engineer investigates your project from a chat page or the Explain button on any catalog resource, using read-only tools inside the project and role you already have.

Off by defaultNeeds a system admin and a provider key
Investigates
Ask why a run failed, what a model feeds or whether a metric looks right. It works through read-only tools (project overview, search, models, lineage, health, jobs, runs, logs, read-only SQL and metrics) and shows each step as it runs. Open it from its own page, or with Explain on any catalog resource.
Read-only
Its tool list is fixed in code and holds no write tools: it cannot edit files, and it cannot trigger or cancel runs.
Your role
It is pinned to the project you opened it in and runs with your own project role, so it can see only what you can see.
Row data
Warehouse rows reach the AI provider only when you tick the row-data option and your role can use the SQL workspace.
Bounded
At most 8 rounds of up to 6 tool calls, 2,500 output tokens per turn and 150,000 tokens per session.
Evidence
Each answer lists the facts it found, with the steps that show them, separately from its own conclusions.
Audit
Every tool call is written to the append-only audit log. Sessions are kept in an AI ledger as hashes and Forewarden-written summaries, not prompts or responses.
Assistant
The same provider key powers single-shot helpers: ask about the project, draft model SQL, documentation and tests as changes you apply or discard, and explain compile, lint and run failures.

A system admin turns it on in Admin → AI with an Anthropic, OpenAI or Azure OpenAI key, then enables the agent; users need the Analyst role or higher. It is in preview: it has been exercised against local provider stand-ins, not yet against a live provider account. The single-shot helpers do not generate semantic models.

§ 08/Warehouses

Thirteen warehouses, and a straight answer on each

Forewarden runs dbt Core through each warehouse's own dbt adapter. Five have run end to end against a real instance; the other eight stay in preview until they have.

  • Tested

    PostgreSQL

    dbt-postgres

  • Tested

    SQL Server

    dbt-sqlserver · incl. Azure SQL

  • Tested

    Oracle

    dbt-oracle

  • Tested

    Trino / Starburst

    dbt-trino

  • Tested

    ClickHouse

    dbt-clickhouse

  • Preview

    Databricks

    dbt-databricks

  • Preview

    Snowflake

    dbt-snowflake

  • Preview

    Google BigQuery

    dbt-bigquery

  • Preview

    Amazon Redshift

    dbt-redshift

  • Preview

    Azure Synapse

    dbt-synapse

  • Preview

    Microsoft Fabric

    dbt-fabric

  • Preview

    Amazon Athena

    dbt-athena

  • Preview

    Teradata

    dbt-teradata

  • Tested

    Run end to end against a real or Dockerized instance of the warehouse.

    Preview

    Validated against the vendor's dbt adapter and driver, but not yet run against a live account.

§ 09/Administer & integrate

The parts an IT review asks about first

Sessions expire (8h idle, 12h absolute) and record IP and client. dbt, git and SQLFluff run with an allowlisted environment, so a project's env_var() can never read the master key.

Security & access

Access
Five project roles, system administrators, Microsoft Entra ID sign-in, TOTP MFA with recovery codes, and passkeys.
Provisioning
SCIM 2.0 (Users, Groups) with group-to-role mappings per project. Deprovisioning ends the user's sessions immediately. Provisioned users sign in with Microsoft Entra ID, the only single sign-on provider today.
Network
CIDR IP allowlist checked on every request before any route runs, with a confirmation step before you exclude your own address.
Audit
Append-only audit log, enforced by a database trigger, with filters and CSV export. Every AI Data Engineer and MCP tool call is recorded in it.

Integrate

REST API
Projects, jobs, runs, trigger, cancel, logs and artifacts, with personal and service tokens that are hashed at rest and revocable.
MCP server
Streamable HTTP at /api/mcp with the same tokens: list models, get lineage and health, search the catalog, trigger and inspect runs, run read-only SQL, query metrics. Each tool has a minimum project role.
Notifications
Email via AWS SES, Slack and Teams incoming webhooks, and generic webhooks signed with HMAC-SHA256.
Secrets
Warehouse credentials and tokens are envelope-encrypted with AES-256-GCM and never reach the browser.

Connect a warehouse. Build your first models this afternoon.

Start with a managed repository and a starter project, or start from a warehouse you already have. On a self-managed deployment an administrator can also connect an existing repository. Thirty days, no card on file.