The reason we typically don't directly edit production data like this is because of application level concerns or validation.
I think it's important that any tool like this allows a way to replicate that safety in some way, otherwise it's as risky as using a GUI client directly. Access control (which this does) addresses security and starts addressing safety, but there's a lot more necessary to get to the safety that is often enforced at the application level.
There's an argument that the validation should be in the database, and that's nice when it's possible, but it's often not. For any application using Rails/Django, anything else along those lines, anyone interacting with the database mostly via an ORM, will typically not be putting this sort of validation in the database in _all_ cases – thinking about enums, fixed slugs, relative dates, timezone support, etc.