Self-serve is in early access

Your warehouse in hours, not weeks.

Ward is a governed data layer for AI agents that connects to existing sources, reconstructs shared metric definitions, and enforces what each agent can read, compute, and write. Your data lake stays where it is.

540+ connectors Read-only by default Bring your own model
  1. 01 Connect Point Ward at what you already run. Read-only, scoped to the objects you name.
  2. 02 Ward AI proposes the relationships It reads the schema and the reports you publish, then drafts how the tables join. You approve each one before it binds.
  3. 03 Agents return findings Scoped to what you approved, and nothing else. Every number carries the SQL that produced it.
What came back Three agents, on the tables approved above
margin-watch 06:47

23 SKUs trending toward zero-on-hand within 48 hours. Replenishment recommendation attached. Priority: dairy and produce categories.

Stockout Prediction →
shrink-watch 06:47

Store #37 showing 4.2% shrinkage vs 1.8% estate average. Pattern suggests receiving dock discrepancy, not shoplifting.

Shrinkage Detection →
availability 06:48

Estate fill rate at 94.2%, up 1.2pp vs last week. Stores 22 and 37 dropped below 85% threshold. Fresh produce is the driver.

Fill Rate Monitoring →

Each card is a real insight type, not a mockup. Click any number in the console and Ward shows the SQL, the source tables and the model that produced it. Every insight type →

Standing it up

Hours, because the slow part was never the compute.

Warehouse projects do not run long because loading data is hard. They run long because nobody can agree what “revenue” means, and that argument has no deadline. Ward starts from the answer your team already publishes.

01

Connect

Point Ward at what you already have. Warehouses, lakes, POS, ERP, finance, ticketing. Read-only credentials, scoped to the tables you name.

Minutes per source. If yours is not one of the managed connectors, the generic JDBC, REST and object-store readers cover most of what is left.

02

Reconstruct

Ward AI reads the reports your team already publishes and rebuilds the definitions sitting behind the numbers in them. It drafts the pipelines, the streams and the cleaning rules; you review the diff. Your metrics, your names for them.

This is the step that usually eats the schedule. Nobody writes down what a metric means. They write down the report that uses it.

03

Run

A working warehouse, a semantic layer your team can read, and an agent runtime you can build against. Query it, or point an agent at it.

No migration window. Your lake stays where it is and Ward reads it in place.

Not a mockup

One take, from an empty source list to a model in the graph.

Recorded against a running tenant. Nothing is sped up and nothing is cut except the login screen.

Ward · connecting a POS export 63s · one take
Describe the export in a sentence. Ward drafts the source, you apply it, the pipeline runs, and the model joins the graph. 63 seconds, unedited, one take. Only the login screen is cut.
Agent runtime

Agents on your data lake fail the security review, not the demo.

The model is never the problem. The problem is that nobody can say what the agent may read, what it did last Tuesday, or what happens when it is wrong. Ward answers those three before you write the first one. Infrastructure for AI needs guardrails, and the name is literal: Ward AI is the warden of your data and your agents.

01

Declare the tables an agent can see. It cannot reach past them.

02

Ward AI drafts the agent definition and its permission scope from a plain-English brief. You approve the scope before it runs.

03

Read-only by default. Write actions require an explicit grant and leave a record.

04

Every query, tool call and result is logged with the agent identity that made it.

05

Model-agnostic. Bring Claude, GPT, Gemini or a model in your own VPC.

How the runtime works →
On the record

Every grant leaves an audit record naming the agent, the person who approved it and the rows it touched.

One log covers people and agents alike, so a reviewer answers one question against one system rather than correlating two.

What it replaces

What you would otherwise buy, and wire together, separately.

LayerWhat it usually isWith Ward
Ingestion Fivetran, Airbyte, custom Python Included. 540 connectors.
Warehouse Snowflake, BigQuery, Databricks Included, or point Ward at the one you have.
Transformation dbt plus an orchestrator Included. Import an existing dbt project.
Semantics A metrics layer nobody adopted Included, and enforced on agents too.
BI Looker, Power BI, Tableau Query and chat included. Keep your BI tool if you want it.
Agents A prototype that failed review Included, with policy and audit.

Ward does not replace your source systems, your CDP, or your data science platform. It reads from all three.

Connectors

Point it at what you already run.

Read-only credentials, scoped to the schemas you name. Schema drift fails the contract instead of writing bad rows for a week.

Warehouses and lakes
SnowflakeBigQueryDatabricksRedshiftSynapseClickHouseDuckDBS3 / IcebergS3 / DeltaGCSAzure Data Lake
Databases
PostgresMySQLSQL ServerOracleMongoDBDynamoDBCassandra
Commerce and POS
ShopifyBigCommerceLightspeedNCR VoyixSquareToastAdyen
ERP and finance
SAPOracle NetSuiteEpicorMicrosoft DynamicsWorkdayQuickBooksStripe
All 540+ connectors →
Where it is running

One enterprise deployment, and the arithmetic behind the rest.

What is running and what is modelled sit in separate boxes, so you can judge each on its own.

Enterprise grocery · nine-figure revenue

Live against POS, ERP and inventory.

Ingestion, the semantic layer and the reasoning on top, running on production systems. Stockouts, shrink, fill rate and assortment are where it starts, because that is where the dollars are.

We do not name operators or publish their numbers without permission. Reference calls get arranged while you are still evaluating. How the engagement is going →

Modelled arithmetic

Where 200 basis points would come from.

Four signals, worked out for a mid-market multi-store estate. Nobody has booked a dollar of it yet.

Fill rate, fewer lost baskets~30 bps
Assortment, better mix and less long tail~50 bps
Shrink, cause-attributed loss~80 bps
Promo, cannibalisation caught mid-flight~40 bps
Modelled EBITDA opportunity~200 bps

Retail is where Ward is deployed, not what Ward is. The retail build →

Pricing

Free to deploy. The number is on the page.

Platform
Free
The whole console, deployed. No license, no seats, no platform fee.
  • Every connector and the semantic layer
  • Unlimited agents and users
  • Policies, audit log, SSO/SAML and RBAC
  • Community support
Request access
Setup
From $0
Self-guided is free. Paid packages when you want a named engineer for training and guidance.
  • Self-guided: $0
  • Guided, two weeks: $7,500
  • Managed, six weeks: $20,000
  • Program, multi-entity: from $50,000
See the setup packages

No seats, no license, no annual plan. How the 5% is metered, and the setup packages with a named engineer, are on the pricing page.

Questions

The six a technical evaluation opens with.

Standing it up

A running warehouse against your sources, a semantic layer with your metric definitions in it, and an API you can query. Not a trial sandbox and not a demo dataset. It assumes your sources are reachable and that someone can approve a read-only role the same day, which is usually the part that decides it.

Because they already exist. Nobody writes down what a metric means, but everybody ships reports that use one. Ward reads the reports your team already publishes and proposes definitions from them. You review the proposals. That review is what usually eats the schedule, and it takes an afternoon when it starts from your own numbers instead of a blank file.

No. Ward registers object storage and reads Iceberg, Delta and Parquet in place. Nothing is copied out to make the warehouse work. That is most of why there is no migration window to schedule.

Agents and security

The tables named in its sources list. Not the ones it can guess, and not the ones a crafted instruction talks it into. Scope is enforced at the query layer, below the model, so prompt injection cannot widen it.

Only with an explicit grant, per table and per action, and you can require a human approval on each one. Every write leaves an audit record naming the agent, the caller and the rows it touched. Read-only is the default and most teams never leave it.

Nothing to deploy. The console, every connector, every agent and every user are free. Ward bills 5% of the model compute that routes through it, on your own provider keys, and that is the only recurring fee. Setup is a one-time package if you want a named engineer for training and guidance, and the smallest one is $0.

Whichever you point it at. Anthropic, OpenAI, Google, or an endpoint inside your own VPC. The policy and audit layer is identical either way, which is the part that survives you changing your mind about models in six months.

Connect one source and see what comes back.

Deploying is free. You pay 5% of the model compute it uses, and nothing else. No call required to find out whether this works on your data.

Find out what your data has been hiding.

Tell us about your operation. We’ll show you the problems Ward catches, and the ones your current tools miss.

Step 1 of 3
What are your goals?
Step 2 of 3
About your operation
Step 3 of 3
Your contact info