<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>SQLGuard field notes</title>
    <link>https://sqlguard.io/blog</link>
    <description>Engineering notes on permission before production writes.</description>
    <language>en-us</language>
    <lastBuildDate>Sat, 01 Aug 2026 15:54:00 GMT</lastBuildDate>
    <atom:link href="https://sqlguard.io/blog/rss.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Connection strings are not change control</title>
      <link>https://sqlguard.io/blog/connection-string-is-not-change-control.html</link>
      <guid isPermaLink="true">https://sqlguard.io/blog/connection-string-is-not-change-control.html</guid>
      <pubDate>Sat, 01 Aug 2026 15:54:00 GMT</pubDate>
      <author>hello@sqlguard.io (SQLGuard)</author>
      <description>Credentials open the door. Receipts govern the write.</description>
    </item>
    <item>
      <title>Human-in-the-loop is not a receipt</title>
      <link>https://sqlguard.io/blog/human-in-the-loop-is-not-a-receipt.html</link>
      <guid isPermaLink="true">https://sqlguard.io/blog/human-in-the-loop-is-not-a-receipt.html</guid>
      <pubDate>Sat, 01 Aug 2026 15:53:00 GMT</pubDate>
      <author>hello@sqlguard.io (SQLGuard)</author>
      <description>A chat yes is a moment. A statement-bound receipt is evidence.</description>
    </item>
    <item>
      <title>Dry-run is not permission</title>
      <link>https://sqlguard.io/blog/dry-run-is-not-permission.html</link>
      <guid isPermaLink="true">https://sqlguard.io/blog/dry-run-is-not-permission.html</guid>
      <pubDate>Sat, 01 Aug 2026 15:52:00 GMT</pubDate>
      <author>hello@sqlguard.io (SQLGuard)</author>
      <description>Sandbox and EXPLAIN are taste. Production execute still needs authorize.</description>
    </item>
    <item>
      <title>Audit logs are after the write</title>
      <link>https://sqlguard.io/blog/audit-logs-are-after-the-write.html</link>
      <guid isPermaLink="true">https://sqlguard.io/blog/audit-logs-are-after-the-write.html</guid>
      <pubDate>Sat, 01 Aug 2026 15:51:00 GMT</pubDate>
      <author>hello@sqlguard.io (SQLGuard)</author>
      <description>Logs explain what ran. Receipts decide whether it was allowed.</description>
    </item>
    <item>
      <title>RLS is not statement authorize</title>
      <link>https://sqlguard.io/blog/rls-is-not-statement-authorize.html</link>
      <guid isPermaLink="true">https://sqlguard.io/blog/rls-is-not-statement-authorize.html</guid>
      <pubDate>Sat, 01 Aug 2026 15:50:00 GMT</pubDate>
      <author>hello@sqlguard.io (SQLGuard)</author>
      <description>Tenant isolation and statement permission solve different failures.</description>
    </item>
    <item>
      <title>CI gate is not production authorize</title>
      <link>https://sqlguard.io/blog/ci-gate-is-not-production-authorize.html</link>
      <guid isPermaLink="true">https://sqlguard.io/blog/ci-gate-is-not-production-authorize.html</guid>
      <pubDate>Sat, 01 Aug 2026 15:48:00 GMT</pubDate>
      <author>hello@sqlguard.io (SQLGuard)</author>
      <description>A green PR check is a rehearsal. Runtime still needs PASS + verify.</description>
    </item>
    <item>
      <title>Readonly flags are not receipts</title>
      <link>https://sqlguard.io/blog/readonly-flag-is-not-a-receipt.html</link>
      <guid isPermaLink="true">https://sqlguard.io/blog/readonly-flag-is-not-a-receipt.html</guid>
      <pubDate>Sat, 01 Aug 2026 15:47:00 GMT</pubDate>
      <author>hello@sqlguard.io (SQLGuard)</author>
      <description>mode=readonly is a kill switch. The intentional write still needs a decision.</description>
    </item>
    <item>
      <title>Which agent_id authorized this?</title>
      <link>https://sqlguard.io/blog/which-agent-authorized-this.html</link>
      <guid isPermaLink="true">https://sqlguard.io/blog/which-agent-authorized-this.html</guid>
      <pubDate>Sat, 01 Aug 2026 15:46:00 GMT</pubDate>
      <author>hello@sqlguard.io (SQLGuard)</author>
      <description>The pager question after an agent mutates production.</description>
    </item>
    <item>
      <title>Access mode is not authorize</title>
      <link>https://sqlguard.io/blog/access-mode-is-not-authorize.html</link>
      <guid isPermaLink="true">https://sqlguard.io/blog/access-mode-is-not-authorize.html</guid>
      <pubDate>Sat, 01 Aug 2026 15:45:00 GMT</pubDate>
      <author>hello@sqlguard.io (SQLGuard)</author>
      <description>Unrestricted / write modes set capability. Permission binds one statement.</description>
    </item>
    <item>
      <title>Client confirm does not travel</title>
      <link>https://sqlguard.io/blog/client-confirm-does-not-travel.html</link>
      <guid isPermaLink="true">https://sqlguard.io/blog/client-confirm-does-not-travel.html</guid>
      <pubDate>Sat, 01 Aug 2026 04:10:00 GMT</pubDate>
      <author>hello@sqlguard.io (SQLGuard)</author>
      <description>Local [y/N] helps one client. Other hosts need a statement-bound receipt.</description>
    </item>
    <item>
      <title>Why Probe is free</title>
      <link>https://sqlguard.io/blog/why-probe-is-free.html</link>
      <guid isPermaLink="true">https://sqlguard.io/blog/why-probe-is-free.html</guid>
      <pubDate>Fri, 31 Jul 2026 18:40:00 GMT</pubDate>
      <author>hello@sqlguard.io (SQLGuard)</author>
      <description>Risk guidance is useful before a write, but guidance is not permission.</description>
    </item>
    <item>
      <title>Authorize is not lint</title>
      <link>https://sqlguard.io/blog/authorize-not-lint.html</link>
      <guid isPermaLink="true">https://sqlguard.io/blog/authorize-not-lint.html</guid>
      <pubDate>Fri, 31 Jul 2026 18:36:00 GMT</pubDate>
      <author>hello@sqlguard.io (SQLGuard)</author>
      <description>Lint inspects a statement. A receipt answers who permitted the write.</description>
    </item>
  </channel>
</rss>
