---
title: "Row-level security"
description: "What is row-level security (RLS)? A database feature that restricts which rows each user or session can see. Learn why it matters for multi-tenant software."
url: https://1flux.ai/glossary/row-level-security
last_updated: 2026-10-10
---

[ERP and platform](https://1flux.ai/glossary#erp-and-platform)

# Row-level security

What is row-level security, and why does it matter when many customers share one database?

Glossary Updated 10 October 2026

Definition

Row-level security (RLS) is a database feature that restricts which rows of a table a user or application session can read or change, based on rules the database enforces itself.

## What is row-level security used for?

In multi-tenant cloud software, many customers’ data can sit in the same tables. Application code normally filters by customer, but a single missed filter could expose one customer’s records to another. With RLS, the database applies the filter to every query on a protected table, so isolation doesn’t depend on application code alone. PostgreSQL, SQL Server and other databases support it.

Example: a policy lets a session read invoice rows only where the tenant ID matches the session’s workspace, so a query that forgets the filter still returns only that workspace’s rows.

RLS complements [role-based access control](https://1flux.ai/glossary/role-based-access-control), which decides what each person may do inside their own workspace.

In 1flux

Each customer’s data is isolated inside the database with PostgreSQL row-level security, which fails closed if the workspace context is missing. [See security and trust](https://1flux.ai/security)

Related

## Keep exploring

### [Role-based access control](https://1flux.ai/glossary/role-based-access-control)

Granting permissions through job roles rather than person by person.

### [Cloud ERP](https://1flux.ai/glossary/cloud-erp)

ERP software hosted by the vendor and used in a browser.

### [Audit trail](https://1flux.ai/glossary/audit-trail)

A record of who changed what, and when.

### [Security](https://1flux.ai/security)

Database-level isolation, access control, audit trails, signed file links and verified backups.

Last updated 10 October 2026
