> ## Documentation Index
> Fetch the complete documentation index at: https://docs.textql.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Wrap-Up

> The recap, as the decision you’d explain to a DBA in an elevator:

The recap, as the decision you'd explain to a DBA in an elevator:

<table><tr><th>Situation</th><th>What you do</th><th>What you maintain</th></tr>
<tr><td>Warehouse supports per-member auth</td><td>Route identity through (Module 1)</td><td>**Nothing new** — your existing policies</td></tr>
<tr><td>Shared service account, policies exist in the warehouse</td><td>Mirror them into guards + drift watch (Module 4)</td><td>The mirror, reviewed like a firewall</td></tr>
<tr><td>Embedded / external users</td><td>Fail-closed guards keyed to trusted scope (Module 3) + TQL-only</td><td>The guards + the test suite</td></tr></table>

## The capstone

```text Prompt theme={null}
For our workspace: list every connection, its enforcement home (warehouse identity / mirrored guards / fail-closed guards), whether its dials match (TQL-only where the ontology enforces), the date the adversarial suite last passed, and any drift-watch alerts outstanding. This is our access-controls posture report — format it for a security review.
```

## Where to go from here

* [**Admin & Governance**](/workshops/admin-governance/overview) — the console-side dials, SSO/SCIM, and audit drills.
* [**Ontology Operations**](/workshops/ontology-operations/overview) — running governed surfaces in production, review routing, golden datasets.
* [**The Context Stack**](/workshops/context-stack/overview) — the behavioral layer: personas whose allowed surfaces match your enforced ones.
* [**Embed TextQL in Your Product**](/workshops/embed-textql/overview) — where the tenant-scoped guard pattern earns its keep.
