plain portal gives you a Python shell into your production app over an encrypted tunnel. Starting one now requires an explicit --read-only or --read-write — no default. The database mode is right there in the command, so a human (or an agent) can judge it before it runs.