I'd with MLF on this one....

as to:-

Apparently one of the users decided to play techie
Considering _what_ was done I wouldn't consider this to be "playing techie", I would consider it to be a malicious act and the (L)user would be disciplined. OTOH, since security was implemented on the database why did you allow a (L)user the ability to alter the security in the first place?