13
I developed a business application at essentially the same time I learned to do non-trivial anything with SQL Server. I give data entry people db_owner and viewers db_datareader.
Now I'm trying to harden things up and the logical thing to my mind is give db_datareader and db_datawriter instread of db_owner, but I'm curious about (a) is this the right thing to do? and (b) what kinds of things can db_owner do that data_writer can't? (i.e. will anything not work after I switch).