<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.appian.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Security Question</title><link>https://community.appian.com/discussions/f/integrations/23325/security-question</link><description>An API I was building required a query of a datastore and to avoid getting a 500 error, I needed to add the service account as a viewer to the datastore. While I don&amp;#39;t particularly care about access to the entity that is getting queried, there are other</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Security Question</title><link>https://community.appian.com/thread/89551?ContentTypeID=1</link><pubDate>Fri, 07 Jan 2022 21:56:31 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:6b7e1622-3970-44bc-9e1a-a3ad8b26fd7d</guid><dc:creator>Marco</dc:creator><description>&lt;p&gt;That was more or less my thinking, but I thought I&amp;#39;d ask anyway as it is better to be safe than sorry.&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Security Question</title><link>https://community.appian.com/thread/89550?ContentTypeID=1</link><pubDate>Fri, 07 Jan 2022 21:50:18 GMT</pubDate><guid isPermaLink="false">d3a83456-d57b-489c-a84c-4e8267bb592a:10b5b192-617b-41a5-b22f-9d991e030840</guid><dc:creator>Mike Schmitt</dc:creator><description>&lt;p&gt;I don&amp;#39;t see what feasible risk this would represent if the service account has viewership access to the general data store - it&amp;#39;s still being given access to the specific API you&amp;#39;re building and that API is still only querying the specific thing you&amp;#39;re telling it to query.&amp;nbsp; It&amp;#39;s not like it enables that user to log in (at all) and even if it was a user that could log in, it&amp;#39;s not as if they would have access to browse the data store or launch arbitrary queries.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>