Databases and storage · Concept

Row Level Security (RLS)

A PostgreSQL feature that decides, row by row, which records each user may see or change, enforced inside the database itself.

Keeping data correct · updated

How it works

With RLS switched on, every query against a table is filtered by policies such as 'a user can read orders whose user_id is their own id'. Because the rule lives in the database, it holds on every path in: the app, an admin script or an automatic API.

It matters most on platforms such as Supabase, where apps query tables directly with a public key. A table with RLS switched off, or with a policy that simply says true, is open to anyone who has that key, so every table's policies deserve a review.

More in Databases and storage

Keeping data correct

All 25 Databases and storage terms

Crafted in the dark. Shipped to the world.

Tell us what you are building. You get a private project space with a proposal and a line-by-line quote within a day.