• I'd try not to give a website account any rights over the underlying data at all, and only Execute rights over stored procs to access the data.

    Am I doing the right thing?