Databases, users & permissions
Give every application the access it needs—and no more.
Separate application data
Create a database for each application when you want to keep its data and permissions separate. Databases on one deployment still share instance resources and plan limits.
Give applications their own users
Create a different user for each application or integration. Assign access only to the databases it needs. Use read-only permissions for reporting tools where possible. Customer users do not receive server root or database superuser access.
Rotate a password safely
Update your application's stored secret as part of a planned rotation. Existing pooled connections may keep working until they reconnect, so verify new connections before revoking old credentials. Resetting a password can interrupt applications using it.
Deletion changes live data
Deleting a user can break an application. Deleting a database removes its data. Check dependencies and the available recovery window before confirming a destructive action.