Plan explorer

Author a policy Compare a snapshot Open a recorded review

Validate a policy and inspect its expansion without a database snapshot. Then compare it with a current-state snapshot: the same Rust planner used by pgroles produces ordered changes, phase analysis, findings, and a graph.

No command exports snapshots yet. Write your own in the snapshot format and scrub role settings and comments by hand first.

Reviewing a native plan? Export a recorded review from the CLI, then open the file below without recalculating it.

Analysis runs in this browser. Snapshot and policy data are not uploaded, persisted, added to URLs, or included in telemetry.

Recorded plan review

Open a sanitized pgroles.review-artifact.v2 export locally. It is shown as recorded without loading the analyzer.

Acme scenario

Adopt Acme safely

Layer Acme’s orders_reader policy onto a database that already has direct access and drift.

Additive mode is the safe first look: it adds declared access while retaining Alice’s direct grant, Bob’s undeclared membership, and undeclared roles in this managed snapshot. Compare adopt and authoritative modes before tightening control.

Desired YAML

Validate, inspect expansion, then compare with the snapshot.

Validate and expand without a snapshot or executor. Password-source declarations are checked without reading environment variables or generating passwords; plan analysis excludes them.

Current snapshot

Adopt Acme safely

Authority graph: complete; a missing path proves no authority

No exporter produces this file yet. Snapshot format and scrubbing

The WASM module is downloaded when you first validate, inspect expansion, or analyze a plan.