dbt Core builds your tables and stops there. Someone still has to look at them, chart them, notice when a number goes strange and show a board to people who do not work in your project. Until now that meant a separate tool with its own users and its own copy of your access rules.
The Lakehouse is our answer. It is a second app that shares your Forewarden sign-in, your projects and your roles. It does not copy any of them. It reads the same role and token data the dbt app already holds, so removing someone from a project removes them here too.
What is in it
A query console runs read-only SQL from the browser against your project's S3-compatible object storage, including Parquet and Iceberg tables, or against a Postgres warehouse. Every run has a row cap, a time limit and an audit row. Notebooks are ordered SQL cells on the same engine, shared as editor or viewer, with encrypted saved outputs. Python cells are not built yet.
Boards are pages of cards. Each card shows one metric from your semantic layer as a number, a table, or a bar, line or pie chart, and you build it from a form, not from typed SQL. You can drill down and share a board with project members by role.
Alerts check on a schedule whether a metric's newest period is an outlier next to the earlier ones. An alert runs as the person who made it, and it tells the notification channels you already set up in Forewarden. A message carries ids and a link. It includes the observed value only if you choose that.
Who sees which rows
Row-level security lets an administrator say, per table, which rows each person or each embed may read. The query engine applies the rules to every query. If it cannot read the rules, it refuses the query rather than run without them. Today an administrator publishes the rules with a script. There is no editor yet, and we would rather say so than hide it.
Embeds put one board, read-only, in an iframe on a page you name. You issue an embed token in Forewarden for 7 to 30 days, give it its own row rule, and revoke it whenever you like. The next request after a revoke fails. The people looking at the board need no account.
Ask Forewarden
Ask Forewarden answers a plain-language question from your dbt project's documented columns, metrics and relationships. Columns and models tagged pii or sensitive are hidden from it, a question that names one is refused before any model is called, and the rows of an answer are never sent to the model. It needs a model provider key from an administrator, and it is in preview: we have not yet measured it against a live provider account. The Lakehouse also has an MCP tool, ask_data_question, for assistants that use Forewarden API tokens with the mcp scope.
What to expect
The Lakehouse is new. It runs as its own stack next to the dbt app and shares its database through a narrow contract, so a self-managed deployment adds a few containers and two internal networks. If you try it and something is unclear or missing, tell us.