Limits & risk model
Row caps, timeouts, plan-based risk scoring, and when confirmation is required.
Two mechanisms keep a curious operator and a production database on speaking terms: hard limits on what a query may pull, and plan-based scoring of what it might cost before it runs.
Limits
- Default sample
- 500 rows.
- Hard cap
- 10,000 rows. The builder offers 500, 1,000, 5,000, or 10,000; the ceiling is not negotiable.
- Query timeout
- 10 seconds.
- Advisory nudge
- Shown when a request exceeds 1,000 rows.
- IN (...) values
- More than 1,000 values in one predicate is a validation error, not a silent trim.
“Download everything” is not a feature. If someone needs a million rows, they can submit a ticket. The limits above apply at every risk-gate setting.
Risk scoring
A run is scored from the query and schema first. Then safe-db asks the database for a plan, and the score may refine. Severity is reported on a fixed scale: Minimal concern, Elevated concern, High concern, Very high concern. The status line tells you where you stand and whether Run is enabled.
The gate itself is tunable in Settings: Cautious blocks Elevated concern and above, Standard (the default) blocks High concern and above, and Flexible’s severity band is Very high concern. Some plan findings (a corroborated scan of a large table, for example) still block any enabled gate, including Flexible.
Off turns off that descriptive scoring. It does not skip the plan: EXPLAIN still runs, and a missing plan still requires confirmation. The row cap and timeout are not part of the dial.
When confirmation is required
- Plan unavailable. No plan evidence means no benefit of the doubt: execution requires explicit confirmation.
- Optimizer cost unavailable. A missing or invalid cost estimate gets the same treatment. A high but valid cost does not; that is a scoring input, not a confirmation trigger.
The Run button says Run. Confirmation is a separate dialog labeled Run with safeguards, not a shrug, not “it was fine in staging.” The limits above still apply afterward; confirmation buys execution, not exemption.