# How sanda works

> What each layer of sanda does, where your data lives, how it flows from a source to an answer, what is computed when, and what is metered.

sanda is a chain of layers, and each one has a single job. Your data passes through them in order, from a source system to an answer. Where it is held, when work happens and what you are charged for follow from that path.

## The path from source to answer

```text
  Your systems and CSV files
            |
            |  managed sync, on a schedule
            v
  sanda warehouse (your own PostgreSQL database, in Sydney)
    raw | derived | mapping
            |
            |  what you put on the map is published to mapping
            v
  Semantic fluid (tables, relationships, metrics, dimensions, filters)
            |
            v
  cherry | sanda search | MCP assistants | Reports | Excel and Power BI
```

1. **Connections** read your source systems on a schedule and land the rows in your warehouse. A CSV upload skips the schedule and lands straight in.
2. **The warehouse** stores them. It is a dedicated PostgreSQL database that belongs to your workspace and to no other. Data arrives in a schema called `raw`.
3. **The [semantic fluid](https://docs.sanda-os.com.au/reference/glossary#semantic-fluid)** is the meaning layer. You put tables on the map, join them, and define what `net revenue` or `active customer` means once. Each table you put on the map is published as a view in the `mapping` schema, so what can be read is what you chose to include.
4. **Everything that answers questions** works from the fluid: cherry, sanda search, assistants connected over [MCP](https://docs.sanda-os.com.au/reference/glossary#mcp), reports, and the Excel and Power BI feed. They agree with one another because they share one set of definitions.

### The schemas in your warehouse

These are the main schemas. You can browse them in the console's **Explorer**.

| Schema | What is in it |
|---|---|
| `raw` | Data as it landed from your sources and CSV files. |
| `derived` | Views, materialized views and procedures you build in **Modelling**. |
| `mapping` | What the semantic fluid publishes for reading: one view per table on the map. |
| `search` | The indexes behind sanda search, if you use it. |

Questions from cherry, from connected assistants, from reports and from the Excel and Power BI feed run through a read-only role that can read `mapping` and cannot read `raw`. Owners and admins can also run their own SQL in the console's SQL shell, and build views in Modelling. Those run with wider access, and the SQL shell records every statement.

## Where your data lives

| What | Where it is held |
|---|---|
| The data you sync or upload | Your workspace's own warehouse, in the [data region](https://docs.sanda-os.com.au/reference/glossary#data-region) chosen when the workspace was created. Workspaces can be created in Australia (Sydney). |
| Search indexes | The same warehouse, beside the rows they came from. |
| Definitions, reports, schedules, settings and chat history | sanda's own database, in Sydney, Australia. |
| Credentials you enter for a source | The managed sync service. They are not kept in sanda's own database. |

Each workspace has its own database and its own credentials, rather than sharing tables with other workspaces. sanda checks that this separation is in force before it serves any workspace data.

Some work happens outside Australia, and sanda says so plainly in the [privacy policy](https://sanda-os.com.au/privacy):

- **AI features.** When cherry answers a question or drafts a definition, the part of your data it needs is sent to an AI model. That can include table and column names, your definitions, small samples of values, and the rows a query returns. Those models run outside Australia, mostly in the United States. Models are called on a zero-data-retention basis, and your data is not used to train anything.
- **sanda search.** It is off until a workspace owner switches it on. Once on, the text of the columns you choose is sent to an embedding model in the United States to build the index.
- **Web traffic.** Requests to the site and the console travel over a global network, so they may be handled at a location outside Australia.

## What is computed when

This is when work happens, and so when the meters move.

| When | What happens |
|---|---|
| **A sync runs**, on its schedule or when you press **Sync now** | The connection reads its source and lands rows in `raw`. Schedules run on a 15 minute grid. |
| **You press Learn from my data** | cherry reads your tables and proposes what they mean. This uses AI. |
| **You ask a question, open a report, or an assistant calls a tool** | The fluid composes a query from your definitions and runs it on the warehouse's compute. This is the moment compute wakes up. |
| **A report is delivered** | Every block re-runs at the moment of sending, so the email carries current numbers. |
| **A search index builds** | After the connection that feeds it lands rows, or on its own schedule. Indexing uses AI. |
| **A task runs** | The views and procedures you built in Modelling refresh, on a schedule, after a connection lands, or by hand. |

A report stores the question each block asks, not the rows. The canvas asks again when you open it, which is why a report, a cherry answer and an emailed pack show the same number.

## What is metered

sanda charges a flat monthly platform fee for the workspace, plus what you use. The console shows usage as it accrues, so an invoice is never the first time you see a number.

| Meter | What it counts |
|---|---|
| **Storage** | The gigabytes your warehouses hold, averaged across the month. |
| **Compute** | The hours your warehouse is working. It scales to zero when idle, and a question wakes it for a minute, so five questions inside that minute count as one. |
| **AI** | Every AI call sanda makes for your workspace, priced by the token: your questions to cherry, and sanda's own work on your data, such as learning and search indexing. A daily limit caps it. |
| **Sync runs** | Each successful run of a managed sync. |

Nothing is priced per seat, report, schedule or connector. A trial draws its A$10 of free credit down on the same four meters and bills nothing. Your edition sets the platform fee, how many warehouses you can hold, and how large each can grow. See [editions](https://docs.sanda-os.com.au/billing/editions), [usage](https://docs.sanda-os.com.au/billing/usage) and [budgets and limits](https://docs.sanda-os.com.au/billing/budgets-and-limits).

## Go further

:::links
- [Core concepts](https://docs.sanda-os.com.au/get-started/concepts): The terms above, each defined and linked.
- [The semantic fluid](https://docs.sanda-os.com.au/semantic-fluid): How the map, metrics and relationships work.
- [Warehouse](https://docs.sanda-os.com.au/warehouse): Provisioning, exploring, SQL and export.
- [Workspace privacy](https://docs.sanda-os.com.au/workspace/privacy): What is held, who can see it, and how to have it deleted.
:::
