>Limit access to the database to a single role, used by a single application, and you absolve so many issues.
This kinda sounds like "Get rid of 90% of the usefulness of having a database"
Of course, maybe you mean make the same data the DB has available via API, or make other users of the data read only.