This is true. No security risk but there is a risk a developer goof’s up, which can happen with privacy rules themselves and how they are configured. Not using a valuable feature for fear of messing up other parts of the function is no reason not to use the valuable feature, but more just highlights the importance of checking our work before deploying live.

I use ignore privacy rules in backend all the time for things that a user should not see but does need to interact with.

1 Like