Consumer access modes
Control Consumer SPARQL and governed source writes without bypassing other permissions
Workspace consumer modes control particular external access paths. Enabling a mode is one condition; the caller still needs operation scopes, resource access, supported targets and applicable grants/policies. These settings do not grant a universal read/write role or turn every connector into a transactional source writer.
You need a Semogram account as owner/admin, or an unrestricted org:manage API key, to change these settings.
Consumer SPARQL
| Mode | Meaning |
|---|---|
| disabled | Consumer SPARQL is unavailable |
| read_only | Permit authorized consumer queries |
| read_write | Also permit authorized consumer updates |
The default is disabled. Query callers need sparql:query; update callers need sparql:update and applicable resource checks. Consumer updates affect current asserted semantic facts; enabling them is distinct from configuring an external fact-store plugin or publishing an ontology query.
Source write access
| Mode | Meaning |
|---|---|
| read_only | Governed source mutation path is not enabled |
| read_write | Allow supported mutations after remaining checks |
The default is read_only. Durable source mutations currently use supported Iceberg endpoints. Ordinary Postgres/MongoDB/S3 destination writes are different pipeline paths. Enabling this setting does not add Iceberg snapshots/recovery to other plugins.
A source write also needs a current snapshot, an approved endpoint policy, caller-specific grant, permitted operation/target and external authorization. Use the Iceberg guide to establish the actual endpoint first.
Example: keep semantic data read-only
In Workspace settings, set Consumer SPARQL access → Allowed operations → Read only and Save SPARQL access. Keep Source write access at Read only unless an intentionally configured mutation workflow needs it. Read back both settings and test a bounded permitted query plus a denied update.
Ask an administrator assistant to inspect the current Consumer SPARQL and source-write modes and explain affected consumers. The exposed MCP settings tools read these modes; apply reviewed changes in the UI or public API.
curl --request PUT "https://platform.semogram.com/api/v1/semantic-api" \
--header "Authorization: Bearer ${SEMOGRAM_ADMIN_KEY}" \
--header "Content-Type: application/json" \
--data '{"mode":"read_only"}'Use GET on that route to read back. Source write settings use GET/PUT /api/v1/source-write-settings with mode read_only or read_write. Both require org:manage.
Read organization_sparql_settings_get and organization_source_write_settings_get on the workspace connection. Both require org:manage and accept empty arguments. They do not change modes.
A mode change does not reverse already committed updates or cancel all active work. Inspect active operations separately before restricting or enabling a path.