From 8a6d480219b1ea00fb4fde7a5fdf84e6b8afbc4a Mon Sep 17 00:00:00 2001 From: Paul Hitt Date: Mon, 28 Sep 2026 16:51:56 -0400 Subject: [PATCH] Say the first README block is a configuration, not a runnable example The two orgScopingRule calls show the same rule configured two ways and do not run on their own. The complete example is under Usage. Co-Authored-By: Claude Opus 5.5 --- README.md | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/README.md b/README.md index b868770..c18fbbd 100644 --- a/README.md +++ b/README.md @@ -16,7 +16,8 @@ org-scoping check for an app that filters by an `org_id` column would flag every handler in an app that has no tenant columns and authorises through RBAC capability checks. One shared script cannot serve both, and a separate copy per app is the wrong fix. So the engine is shared and the patterns are -parameters. +parameters. Two configurations of the same rule (a complete, runnable example +is under Usage): ```ts // An app that scopes rows by tenant column