3306. Use the Resource
access name as the client username and enter a short-lived Forge token as the
password.
Policy fields and actions
Forge can match database, destination user, command, tables, and a literal-free query pattern. Ordinary and prepared commands and bounded multi-statement admission are supported. Connections and commands can be allowed, flagged, approved, or blocked. Forge can redact exact result columns or remove matching rows. Filtering runs before redaction and preserves framing andNULL. Text-protocol values support
the shared redaction strategies and scalar comparisons. Binary results can
always be nullified; other strategies require a supported textual column.