What guarantees do you offer with query security if I turn this over to an end user? How do I keep them only accessing their own data?
You can read more on how to do that on Postgres here https://www.2ndquadrant.com/en/blog/application-users-vs-row...
This blog discusses how to do that on Postgres
https://www.2ndquadrant.com/en/blog/application-users-vs-row...