You hand an engineer urgent production access. They fix the issue, but also peek at a few unrelated databases because, well, they can. It is not malice, it is human nature. The problem is that session-based access treats the whole connection as trusted. That is why per-query authorization and run-time