Row-Level Security (RLS)
Row-level security (RLS) is a database feature that decides which rows a query may read or change based on who is running it, enforced by the database itself rather than by application code.
In PostgreSQL, RLS is switched on per table with ALTER TABLE ... ENABLE ROW LEVEL SECURITY and defined with CREATE POLICY rules, typically comparing a column such as user_id to the identity of the signed-in user. It matters most on platforms that let the browser talk to the database directly with a public key, such as Supabase: there, RLS is the entire authorization layer, and a table without it is readable by anyone holding the key that ships in every page. Note that table owners bypass RLS unless it is forced, and superusers and roles with BYPASSRLS always do, so a policy is only as strong as the role the application connects with. In September 2026, researchers found more than 16,000 Supabase databases readable because RLS was missing.
See also: authentication vs authorization, ABAC, least privilege, Supabase Auth
Related on Start with Identity
- GlossaryCIEM
Cloud Infrastructure Entitlement Management. Tools that discover and right-size identities and permissions across AWS, Azure, and GCP, reducing excessive and un
- GlossaryEntitlement
A specific permission or right an identity holds over a resource. Governance and CIEM exist to keep entitlements understood, justified, and minimal. Entitlement
- GlossaryFine-Grained Authorization (FGA)
Authorization at the level of individual resources or fields, rather than at the application or role level. Critical for multi-tenant SaaS, collaborative docume
- BlogWebAuthn Level 3 is a W3C Recommendation, and it standardises the parts everyone already shipped
W3C published WebAuthn Level 3 as a Recommendation on August 25, 2026. Conditional create, the Signals API, Related Origin Requests, and the PRF extension stop