> What I'm not seeing is how do you ..
You can write fairly complex rules with the access control layer ! The first two conditions are possible (except for the project is only visible on Mondays).
allow select on rows which satisfy this property:
{ "project_type" : { "_eq" : "whatever" } }
allow update on rows which satisfy this property:
{ "closed_data" : { "_is_null" : true } }
The idea is simple, we provide a boolean expression based access control layer which can use variables from headers. When you can't specify it using the access control layer, you can write this in your own graphql layer and schema stitch with hasura. So you only have to write what is not possible with the access control layer.
> The other point I don't see is how do you ...
You can use the tooling around Postgres ! You can create an `ON INSERT` trigger on the table and listen to these events.
We're launching something very cool in the subscriptions/event-source to solve these kinds of problems. We also have 2 nice projects that work independent of the graphql-engine to help with change subscription on postgres (skor[1], pgdeltastream[2])
[1] https://github.com/hasura/skor
[2] https://github.com/hasura/pgdeltastream