# Desk log NMD-ROD-20260822

**Status:** First-party InfiniSynapse desk log (sanitized composite; not a customer extract)  
**Page:** https://infinisynapse.com/en/blog/read-only-database-for-ai  
**Run ID:** `NMD-ROD-20260822`  
**Date:** 2026-08-22 (Saturday)  
**Operator:** InfiniSynapse Data Team  
**Attestor:** William Zhu, InfiniSynapse cofounder ([GitHub @allwefantasy](https://github.com/allwefantasy))  
**Contact for contradictions:** zhuhl@infinisynapse.com

## What this file is

A downloadable record of reusing an old BI role that still had `UPDATE` versus revoking write, proving the revoke, then connecting SELECT-only. It is **not** a named-logo customer case, a vendor bake-off, or a Creative Commons / Schema.org / PostgreSQL experiment.

## Four-step method (reproducible)

1. Create a dedicated role. Grant SELECT. Revoke INSERT, UPDATE, DELETE, and DDL.
2. Prove the revoke with a write that must fail. Prefer a replica if the primary is busy.
3. Ask one goal: Q2 refund rate by channel, paid orders as denominator, exclude test accounts.
4. Inspect SQL. Confirm SELECT-only. Re-run after the channel note is bound.

## Source and goal

| Field | Value |
|---|---|
| Sources | Postgres reporting replica; 13 order-related tables; ~2.2 million paid-order rows |
| Standing goal | Q2 refund rate by channel, paid orders as denominator, exclude test accounts |
| Contrast | Reuse old BI role vs revoke then connect |

## Results

| Retrieval state | Write revoked (proof) | SELECT-only connected | SQL inspectable |
|---|---|---|---|
| Reuse old BI role | 0 | 0 | 0 |
| Revoke then connect | 1 | 1 | 1 |

Wall-clock for the successful revoke rerun: 10 minutes (warehouse time excluded). The clock started when the operator opened the standing goal and ended when the failed write, the SELECT-only connect, and the inspectable SQL sat side by side.

## What you may cite

- Artifact counts 0/0/0 → 1/1/1, 13 tables + ~2.2M paid-order rows on this run, ~10 min wall-clock, run ID

## What you may not claim

- Customer uplift %, a safer vendor, official EEAT score, named-logo case, or that Creative Commons / Schema.org / PostgreSQL / Gartner / WAIC scored this run

## Independent context (not this run)

- [Creative Commons licenses](https://creativecommons.org/licenses/) (retrieved 2026-08-29)
- [Schema.org documents](https://schema.org/docs/documents.html) (retrieved 2026-08-29)
- [YAML 1.2.2](https://yaml.org/spec/1.2.2/) (retrieved 2026-08-29)
- [Protocol Buffers overview](https://protobuf.dev/overview/) (retrieved 2026-08-29)
- [Apache Avro specification](https://avro.apache.org/docs/current/specification/) (retrieved 2026-08-29)
- [PostgreSQL Privileges](https://www.postgresql.org/docs/current/ddl-priv.html) (retrieved 2026-08-29)
- [PostgreSQL REVOKE](https://www.postgresql.org/docs/current/sql-revoke.html) (retrieved 2026-08-29)
- [NIST AI Risk Management Framework](https://www.nist.gov/itl/ai-risk-management-framework) (retrieved 2026-08-29)
- [ISO/IEC 9075](https://www.iso.org/standard/76583.html) (retrieved 2026-08-29)
- [W3C DCAT](https://www.w3.org/TR/vocab-dcat-3/) (retrieved 2026-08-29)
- [DataCite](https://datacite.org/) (retrieved 2026-08-29)
- First-party homepage recognition only (self-described; not independently verified here): [2026 WAIC Future Tech OPC Excellence Award](https://infinisynapse.com/#recognition)

## Machine-readable aggregate

- [aggregate-NMD-ROD-20260822.csv](https://infinisynapse.com/blog-media/read-only-database-for-ai/downloads/aggregate-NMD-ROD-20260822.csv)
- [verify-NMD-ROD-20260822.py](https://infinisynapse.com/blog-media/read-only-database-for-ai/downloads/verify-NMD-ROD-20260822.py)

**Last verified:** 2026-08-29
