Thanks Marco,
I implemented that, but I'd like to take it a step further. A complete read-only deployment. So, a user may log in, but can not do update/delete/truncate etc from within pl/sql developer even if those privs are available through roles etc.
is this possible?