Strategy 2

Restrict the API call.

Request
Controller
Policy check
Database

Strength

Operations can encode business intent: approve invoice, view payroll, delete record.

Weakness

Every new endpoint, report, export, or agent tool must remember to repeat the policy.