Overview
A public client key without row-level access controls can allow one user to read, modify, or delete other users' records. Database policies must restrict each identity to the rows and actions it is meant to access. This is a small configuration step with a large effect on common application failures.