Definition
Row-level security (RLS) is a database feature that restricts which rows of a table a user or application session can read or change, based on rules the database enforces itself.
What is row-level security used for?
In multi-tenant cloud software, many customers’ data can sit in the same tables. Application code normally filters by customer, but a single missed filter could expose one customer’s records to another. With RLS, the database applies the filter to every query on a protected table, so isolation doesn’t depend on application code alone. PostgreSQL, SQL Server and other databases support it.
Example: a policy lets a session read invoice rows only where the tenant ID matches the session’s workspace, so a query that forgets the filter still returns only that workspace’s rows.
RLS complements role-based access control, which decides what each person may do inside their own workspace.