Start with Identity
Concept

Row-Level Security (RLS)

Row-level security (RLS) is a database feature that decides which rows a query may read or change based on who is running it, enforced by the database itself rather than by application code.

In PostgreSQL, RLS is switched on per table with ALTER TABLE ... ENABLE ROW LEVEL SECURITY and defined with CREATE POLICY rules, typically comparing a column such as user_id to the identity of the signed-in user. It matters most on platforms that let the browser talk to the database directly with a public key, such as Supabase: there, RLS is the entire authorization layer, and a table without it is readable by anyone holding the key that ships in every page. Note that table owners bypass RLS unless it is forced, and superusers and roles with BYPASSRLS always do, so a policy is only as strong as the role the application connects with. In September 2026, researchers found more than 16,000 Supabase databases readable because RLS was missing.

See also: authentication vs authorization, ABAC, least privilege, Supabase Auth

Last reviewed By SWI Community TeamSuggest a correctionHow we research