Review policies as application controls
Row-level security controls database operations for the role and request context that reaches PostgreSQL. Review it with schema, identity claims, API behaviour, and privileged server paths. A policy that passes under an administrator connection says little about a browser user.
Inventory tables and actors
List tables, operations, tenant keys, ownership fields, user roles, service credentials, views, functions, and API routes. For each operation, state who may read, insert, update, and delete. Include background jobs and support tools that can bypass ordinary client policy.
Test allowed and denied actions
Use normal accounts to test an allowed action, another tenant's record, ownership-field manipulation, guessed identifiers, bulk reads, and direct API requests. Test inserts and updates separately: a policy that allows creation can still permit a user to assign a record to another tenant if checks are incomplete.
Review changes and exceptions
Treat policy, schema, role, and API changes as a single review set. Keep privileged service keys only in trusted server paths, document every exception, and rerun a regression suite after migrations. OWASP guidance supports testing authorisation at every sensitive operation, not only the user interface.
RLS review record
Keep a testable decision per table.
| Operation | Allowed actor | Denial test |
|---|---|---|
| Read | Tenant member | Other tenant ID. |
| Insert | Authorised creator | Forged tenant or owner. |
| Update | Record owner or role | Ownership reassignment. |
| Delete | Defined owner | Guessed record ID. |
Questions to resolve
Can frontend hiding enforce access?
No. Test the database and API route with a normal identity.
Do service keys bypass policies?
Treat privileged credentials as a distinct server-only exception and review their use.
What is acceptance evidence?
A repeatable suite showing allowed and cross-tenant denied operations for each important table.
Review cycle
Inventory tables, roles, policies, and privileged paths.
Run allowed and denied requests through the actual API.
Rerun after schema, identity, policy, or client changes.
Review checks
Keep results beside migrations.
Role matrix
Operations and actors are stated.
Cross-tenant test
A normal account cannot retrieve or change another tenant's data.
Privileged path
Server-only exceptions are inventoried and tested.

