Strategy 3

Restrict the data itself.

public profile graph
team project graph
payroll graph
legal hold graph

The user does not query the database. The user queries an authorized view of the database.