# row-level-security

Source: https://startwithidentity.com/glossary/row-level-security/
Last updated: 2026-09-29
License: content by Start with Identity. Cite the source URL.

---

Row-level security (RLS) is a database feature that decides which rows a query may read or change based on who is running it, enforced by the database itself rather than by application code.

In PostgreSQL, RLS is switched on per table with `ALTER TABLE ... ENABLE ROW LEVEL SECURITY` and defined with `CREATE POLICY` rules, typically comparing a column such as `user_id` to the identity of the signed-in user. It matters most on platforms that let the browser talk to the database directly with a public key, such as Supabase: there, RLS is the entire authorization layer, and a table without it is readable by anyone holding the key that ships in every page. Note that table owners bypass RLS unless it is forced, and superusers and roles with `BYPASSRLS` always do, so a policy is only as strong as the role the application connects with. In September 2026, researchers found more than [16,000 Supabase databases readable because RLS was missing](https://startwithidentity.com/blog/2026-09-28-16000-supabase-databases-readable-because-row-level-security-was-off/).

See also: [authentication vs authorization](https://startwithidentity.com/guides/fundamentals/authentication-vs-authorization/), [ABAC](https://startwithidentity.com/glossary/abac/), [least privilege](https://startwithidentity.com/glossary/least-privilege/), [Supabase Auth](https://startwithidentity.com/vendors/open-source/supabase-auth/)
