Plan explorer
Author a policy Compare a snapshot Open a recorded review
Validate a policy and inspect its expansion without a database snapshot. Then compare it with a current-state snapshot: the same Rust planner used by pgroles produces ordered changes, phase analysis, findings, and a graph.
No command exports snapshots yet. Write your own in the snapshot format and scrub role settings and comments by hand first.
Reviewing a native plan? Export a recorded review from the CLI, then open the file below without recalculating it.
Recorded plan review
Open a sanitized pgroles.review-artifact.v2 export locally. It is shown as recorded without loading the analyzer.
Acme scenario
Adopt Acme safely
Layer Acme’s orders_reader policy onto a database that already has direct access and drift.
Additive mode is the safe first look: it adds declared access while retaining Alice’s direct grant, Bob’s undeclared membership, and undeclared roles in this managed snapshot. Compare adopt and authoritative modes before tightening control.
Desired YAML
Validate, inspect expansion, then compare with the snapshot.
Validate and expand without a snapshot or executor. Password-source declarations are checked without reading environment variables or generating passwords; plan analysis excludes them.
Current snapshot
Adopt Acme safely
Authority graph: complete; a missing path proves no authority
No exporter produces this file yet. Snapshot format and scrubbing
The WASM module is downloaded when you first validate, inspect expansion, or analyze a plan.