Suppose your application has a notes table. Every note belongs to a specific user. Without the correct database policy, you could accidentally expose one user's notes to another.
Add a User ID
Your table should contain a field identifying the owner. For example:
user_id
This can reference the authenticated user's ID.
Enable RLS
Turn on Row Level Security for the table.
Create a Read Policy
The read policy should compare the record owner with the authenticated user. Conceptually: record.user_id = current authenticated user
Protect Inserts
When creating a new note, make sure the inserted user_id corresponds to the current user.
Protect Updates
Users should only be able to update their own notes.
Protect Deletes
The same ownership rule should apply to deleting records.
Test the Full CRUD Flow
Test all four operations:
Create → Read → Update → Delete
Then repeat the tests with a second account.
This helps verify that your database security matches your application's intended behavior.