Beyond Text-to-SQL: Why Enterprise Analytics Needs Governed APIs

Tags
New Dialpad research shows how an agentic system can turn natural-language questions into secure, accurate analytics through enterprise APIs—not direct database access.
Every business should truly know its customers. But customer understanding only creates value when people can ask the right questions, get a trustworthy answer, and act on it.
For many organizations, that is harder than it sounds. The data may exist, but it lives behind complex business-intelligence tools, domain-specific interfaces, and governance rules designed to protect sensitive information. Text-to-SQL has made natural-language access to data more approachable, but enterprise analytics rarely runs on a direct database connection. It runs through governed APIs that enforce permissions, shared metric definitions, tenant boundaries, logging, and business rules.
That distinction is the focus of our paper, Beyond Text-to-SQL: An Agentic LLM System for Governed Enterprise Analytics APIs. In the paper, we introduce Analytic Agent, an LLM-based system that translates natural-language analytics requests into secure interactions with enterprise analytics APIs. Rather than asking a model to produce SQL, the system helps resolve what a person means, identify the right organizational targets, verify access, select an API endpoint, create a schema-compliant request, execute it safely, and return a policy-aware visualization when appropriate.
A query that runs can still be wrong
The central challenge in enterprise analytics is not simply generating an executable query. It is generating the right answer for the right person, based on the right metric, target, and time range.
Consider a question such as: “Show weekly average handle time for the Seattle support team over the last quarter.”
A useful system has to do more than identify a handle-time metric. It must determine which “Seattle support team” the user means, verify that the user has access to that team’s data, select the appropriate analytics endpoint, calculate the relevant date range, build a valid request, and present the result in a meaningful format.
Each of those steps can fail in a different way. A request may be structurally valid yet still point to the wrong target, apply the wrong filter, or answer a subtly different question than the user asked.
That is why the system separates responsibilities. The LLM interprets intent and selects tools. The platform retains control of authentication, metric definitions, permissions, audit logging, validation, and rendering rules. The model acts as a planner over stable, structured interfaces—not as the repository of enterprise business logic.
From natural language to governed action
Analytic Agent coordinates four LLM-powered subsystems:
Orchestration: Interprets the request, manages session state, and guides the workflow from intent to answer.
Target grounding and permissions: Resolves incomplete references such as teams, offices, or call centers into concrete entities, then verifies access.
Database querying over governed APIs: Selects an endpoint, constructs a validated payload, and uses deterministic date-processing functions to reduce errors in time-based requests.
Visualization as structured generation: Produces policy-aware chart specifications from tabular results while applying the same permissions and masking rules as the underlying data.
The architecture is designed for a practical enterprise reality: governance cannot be an afterthought. A system that returns a compelling answer but exposes an inaccessible target, misapplies a shared metric, or bypasses policy is not useful in production.
Measuring answers, not just requests
We evaluated the system on 90 enterprise analytics tasks curated by domain experts. The tasks represented production schemas and included point metrics, trend lines, categorical breakdowns, and varying levels of target specificity.
The strongest model in the study, Gemini 2.5 Pro, achieved a 96.67% query execution success rate and 77.22% end-to-end accuracy. Gemini 2.5 Flash achieved 94.44% execution success and 71.67% end-to-end accuracy, providing a competitive balance of reliability and efficiency for production deployment.
The difference between those two measures matters. Execution success shows whether the request is structurally valid and can run. End-to-end accuracy asks a stricter question: does the returned value, entity scope, and temporal or filter semantics match the intended answer?
A query that executes is necessary. It is not sufficient.
Building a more useful interface to enterprise intelligence
Dialpad is the AI platform for customer experience. That means helping businesses turn conversations and operational data into context, decisions, and action—without sacrificing the governance customers depend on.
Analytic Agent illustrates a broader architectural principle for enterprise AI: the LLM should not replace the systems that define and protect the business. It should help people navigate those systems more naturally.
When an agent works over governed APIs, it can make data more accessible to non-technical users while preserving the controls that make enterprise analytics trustworthy in the first place. The result is not simply a better way to query data. It is a more practical way to turn organizational intelligence into informed action.
Beyond Text-to-SQL: An Agentic LLM System for Governed Enterprise Analytics APIs is by Gundeep Singh, Parsa Kavehzadeh, Jing Xia, Xue-Yong Fu, Julien Bouvier Tremblay, Md Tahmid Rahman Laskar, Vincent Lum, and Shashi Bhushan TN of Dialpad.
