executing command of each session, along with its identifier and the
time when that command began execution. This parameter is on by
default. Note that even when enabled, this information is not
- visible to all users, only to superusers, members of the
- <literal>pg_read_all_stats</literal> role and the user owning
- the session being reported on, so it should not represent a
- security risk.
+ visible to all users, only to superusers, roles with privileges of the
+ <literal>pg_read_all_stats</literal> role and the user owning the
+ sessions being reported on (including sessions belonging to a role they
+ have the privileges of), so it should not represent a security risk.
Only superusers can change this setting.
</para>
</listitem>