Grant least-privilege roles; never let apps use superuser | BeforeMerge Rules | BeforeMerge