Semogram Docs
Workspace managementWrite controls

Consumer access modes

Control Consumer SPARQL and governed source writes without bypassing other permissions

Workspace consumer modes control particular external access paths. Enabling a mode is one condition; the caller still needs operation scopes, resource access, supported targets and applicable grants/policies. These settings do not grant a universal read/write role or turn every connector into a transactional source writer.

You need a Semogram account as owner/admin, or an unrestricted org:manage API key, to change these settings.

Consumer SPARQL

ModeMeaning
disabledConsumer SPARQL is unavailable
read_onlyPermit authorized consumer queries
read_writeAlso permit authorized consumer updates

The default is disabled. Query callers need sparql:query; update callers need sparql:update and applicable resource checks. Consumer updates affect current asserted semantic facts; enabling them is distinct from configuring an external fact-store plugin or publishing an ontology query.

Source write access

ModeMeaning
read_onlyGoverned source mutation path is not enabled
read_writeAllow supported mutations after remaining checks

The default is read_only. Durable source mutations currently use supported Iceberg endpoints. Ordinary Postgres/MongoDB/S3 destination writes are different pipeline paths. Enabling this setting does not add Iceberg snapshots/recovery to other plugins.

A source write also needs a current snapshot, an approved endpoint policy, caller-specific grant, permitted operation/target and external authorization. Use the Iceberg guide to establish the actual endpoint first.

Example: keep semantic data read-only

In Workspace settings, set Consumer SPARQL access → Allowed operations → Read only and Save SPARQL access. Keep Source write access at Read only unless an intentionally configured mutation workflow needs it. Read back both settings and test a bounded permitted query plus a denied update.

Ask an administrator assistant to inspect the current Consumer SPARQL and source-write modes and explain affected consumers. The exposed MCP settings tools read these modes; apply reviewed changes in the UI or public API.

Set Consumer SPARQL read-only
curl --request PUT "https://platform.semogram.com/api/v1/semantic-api" \
  --header "Authorization: Bearer ${SEMOGRAM_ADMIN_KEY}" \
  --header "Content-Type: application/json" \
  --data '{"mode":"read_only"}'

Use GET on that route to read back. Source write settings use GET/PUT /api/v1/source-write-settings with mode read_only or read_write. Both require org:manage.

Read organization_sparql_settings_get and organization_source_write_settings_get on the workspace connection. Both require org:manage and accept empty arguments. They do not change modes.

A mode change does not reverse already committed updates or cancel all active work. Inspect active operations separately before restricting or enabling a path.