問題文
The maintenance knowledge base is exposed through REST, GraphQL, and MCP endpoints by one Data API builder deployment. A partner application must read only the published work order view and must not reach anything else. How does the team bound it?
選択肢
- Turn off the GraphQL and MCP surfaces globally, since bounding one consumer requires removing the other protocols.
- Grant the partner a database user with SELECT on the base work order tables and let the endpoints pass the request through.
- Rely on the Anonymous system role, which is limited to read operations by design.
- Expose the view as an entity, grant the read action to a dedicated role on that entity only, and have the partner's requests select that role, because no role has default permissions.