Runs where the database is.
- ·Windows service, Linux systemd, or Docker container.
- ·Holds the real connection string locally; opens it only to scan or run a query.
- ·Outbound TLS to the control plane, no inbound ports.
- ·Performs read-only metadata scans for documentation.
- ·Executes ad hoc queries and scheduled exports under a read-only role.