Limits & risk model

Row caps, timeouts, plan-based risk scoring, and when confirmation is required.

Two mechanisms keep a curious operator and a production database on speaking terms: hard limits on what a query may pull, and plan-based scoring of what it might cost before it runs.

Limits

Default sample
500 rows.
Hard cap
10,000 rows. The builder offers 500, 1,000, 5,000, or 10,000; the ceiling is not negotiable.
Query timeout
10 seconds.
Advisory nudge
Shown when a request exceeds 1,000 rows.
IN (...) values
More than 1,000 values in one predicate is a validation error, not a silent trim.

“Download everything” is not a feature. If someone needs a million rows, they can submit a ticket. The limits above apply at every risk-gate setting.

Risk scoring

A run is scored from the query and schema first. Then safe-db asks the database for a plan, and the score may refine. Severity is reported on a fixed scale: Minimal concern, Elevated concern, High concern, Very high concern. The status line tells you where you stand and whether Run is enabled.

The gate itself is tunable in Settings: Cautious blocks Elevated concern and above, Standard (the default) blocks High concern and above, and Flexible’s severity band is Very high concern. Some plan findings (a corroborated scan of a large table, for example) still block any enabled gate, including Flexible.

Off turns off that descriptive scoring. It does not skip the plan: EXPLAIN still runs, and a missing plan still requires confirmation. The row cap and timeout are not part of the dial.

When confirmation is required

  • Plan unavailable. No plan evidence means no benefit of the doubt: execution requires explicit confirmation.
  • Optimizer cost unavailable. A missing or invalid cost estimate gets the same treatment. A high but valid cost does not; that is a scoring input, not a confirmation trigger.

The Run button says Run. Confirmation is a separate dialog labeled Run with safeguards, not a shrug, not “it was fine in staging.” The limits above still apply afterward; confirmation buys execution, not exemption.

safe-db is proudly opensource. Apache License 2.0.

GitHub