Ask HN: How do you keep employee eyes off production data in new startup?
I just had a thought about my tentative next project, that I'd have to be very careful typing `npx prisma studio` (or run any other generic database browser), such as when debugging or doing database surgery, because it would be too easy to accidentally glimpse information that should be private to the users. And I couldn't look at some tables at all this way.
What are some low-cost, viable ways for an early startup to isolate this private data from founders&employees even accidentally seeing it?
An obvious measure you'd do in any case is to have a separate "prod" database, which is harder to access, and by fewer people. (You can usually work with dummy data instead.) But even then you'll need to go in there sometimes. And also there's debugging logs that more people are likely to see, more often, which can leak information.
So more than that is needed.
Also, especially if you're dogfooding something like social media, there's the possibility that some employee might be very motivated to access user data intentionally (e.g., the "LOVEINT" problem, or when a Reddit exec showed off their power inappropriately). Access logging can help with this, but can be circumvented, and is also runway-expensive to implement.