Our decision log · 4 August 2026
Make the application unable to read captured email content
ReversedA real decision from building Decize, written down before the outcome.
- The decision
- Add row-level security (migration 0029) so that even the application could not read the body of a captured message.
- Why, at the time
- Handing a product your inbox is the moment you should be suspicious of it, and a guarantee enforced by the database is worth more than a promise in a policy.
- What happened
- The organization-only migration two changes later dropped the policies, the function and the column, and nobody noticed at the time. The guarantee is gone; the site now says plainly that every active member can read the ledger and the captured mail behind it.
- Lesson
- A guarantee a later migration can silently remove was never a guarantee. If it matters, something has to fail loudly when it disappears.
Every entry in this ledger is real and was checked against the commit or migration that carries it. Want to keep your own this way? Start with the free decision log template.