The point is to allow untrusted clients (browser/mobile) to run (safe/predictable) queries against your database without the need for "backend/api" as a middle layer because nowadays most of the business logic is mostly on the frontend and it needs a way to get to the database.
It's not necessarily useful if you have trusted code running on your servers, it should just connect to the database. But if this works for you ... why not.
(At least that's how i think of it, others may use it in different ways)