diff --git a/README.md b/README.md index b868770..c18fbbd 100644 --- a/README.md +++ b/README.md @@ -16,7 +16,8 @@ org-scoping check for an app that filters by an `org_id` column would flag every handler in an app that has no tenant columns and authorises through RBAC capability checks. One shared script cannot serve both, and a separate copy per app is the wrong fix. So the engine is shared and the patterns are -parameters. +parameters. Two configurations of the same rule (a complete, runnable example +is under Usage): ```ts // An app that scopes rows by tenant column