When security is not integrated into a database, it is often handled externally by a trusted front-end application that controls user access and filters queries. Internal database mechanisms like views or cell suppression cannot compensate if base access is unmanaged.