Skip to main content
Version: v12

Dataset Write

BrinqaIQ can create, update, and delete records of your writable data models, and bulk-update a single attribute across many records at once. This capability is available in two ways:

  • BrinqaIQ Assistant (chat UI): ask in natural language to create, change, or remove records. BrinqaIQ handles the orchestration in the conversation.
  • MCP integration: the dataset write tools let any MCP-compatible AI client mutate records from agent prompts without leaving the client. See MCP Integration for setup.

These tools are the write counterpart to BQL: reading data stays on the BQL tools, and every mutation goes through the dataset write tools. Every operation runs with the permissions of the user account tied to your API token, so an agent only ever changes records you can already access. You never tell the agent which application to write to; the application is derived from the data model.

How it works​

BrinqaIQ groups dataset write operations into two areas:

  • Single records: create, update, or delete one record at a time. The tools are dataset.create, dataset.update, and dataset.delete.
  • Bulk update: set one attribute to one value on every record matched by a BQL query, with dataset.bulkUpdate.

A record is identified by its data model and its numeric record id. To set a relationship, the agent uses the related record's id, so it resolves a named entity to its id with a BQL query first. For single-record writes, the agent uses the concrete model that holds the records (for example Vulnerability), never an abstract parent such as Finding, Asset, or Ticket.

Create a record​

dataset.create creates one record of a data model from a set of attribute values.

Example agent prompt:

Create a Vulnerability named "OpenSSL CVE-2026-0001" with severity High.

The agent calls dataset.create and reports the new record's id, which you can use in a follow-up update or delete.

Update or delete a record​

dataset.update changes attributes on one record, and dataset.delete removes one record. Each attribute you ask to change replaces its stored value; for a multi-valued attribute, the agent sends the full list the record should end with. A consolidated record can be deleted only when its sole source is manual entry.

Because both change stored data, an annotation-aware client (such as Claude Desktop) shows a confirmation prompt summarizing the change before the tool runs, so the write never happens without your approval.

Example agent prompts:

Set the severity of Vulnerability 1847261953084 to Critical.

Delete Vulnerability 1847261953084.

The agent calls dataset.update or dataset.delete, and the client asks you to confirm before the change is applied.

Bulk-update an attribute​

dataset.bulkUpdate sets a single attribute to one value on every record matched by a BQL query. You describe the records with a query and name the one attribute to set; the agent launches the platform's data-update flow, which runs asynchronously, and reports a transactionId you can use to follow progress.

A few things are specific to bulk update:

  • The attribute must have Bulk updating enabled in its data model configuration. The agent surfaces a clear error when it is not.
  • For a multi-valued attribute, you can choose how the value is applied: replace the whole list (the default), add to it, or remove from it.
  • Unlike the single-record tools, bulk update can target an abstract parent model (such as Finding or Asset): the query selects the records and the platform applies the change to each one by its concrete type. You can also update an attribute a model inherits from a parent.

Because it changes stored data across many records, bulk update shows a confirmation prompt before it runs.

Example agent prompts:

Set severity to Critical on every Vulnerability with a CVSS score of 9 or above.

Add the tag "exploited-in-wild" to every Vulnerability matched by that query.

The agent calls dataset.bulkUpdate, asks you to confirm the change and the records it will affect, and then launches the update and reports the transactionId.