Working notes
The parts that decide whether it survives.
Not product notes. These are the questions we end up answering in evaluations and handover meetings — record-level access control, what owning generated code actually means, and the tools nobody approved — written out properly so we can point at them.
The guides
Row-level security, and why it belongs in the database
What row-level security is, the three places teams put record-level rules, why the ones written in application code eventually leak, and the checks that tell you whether yours actually holds.
- Two questions that get confused for one
- The three places the rule ends up
- The rule is a path through your data
- Multi-tenancy is this problem wearing a suit
- How to tell whether yours actually holds
- How this works on our platform
Who owns the code an AI tool writes for you?
Ownership, readability and portability are three separate questions hiding inside “do we own it”. What the law is unsettled about, what the contract decides, and the exit test that answers it in practice.
- The three questions
- The legal part, honestly
- What to read in the terms
- The exit test
- Where we stand
Shadow IT is a symptom, not a crime
Why departments build their own systems, which risks are real and which are theatre, how to find what exists without starting a witch hunt, and how to make the sanctioned path faster than the unsanctioned one.
- Why it happens
- The risks that are real, in order
- Finding it without a witch hunt
- Deciding what happens to each one
- Making the approved path the fast one
Ask a person
Something here you disagree with?
These are written from what we run into, not from a keyword list. If your experience says otherwise, we would genuinely like to hear it — and if you have a question none of them answer, ask a person.