Live RLS from Base44 + recommended rules from Role Matrix
How "Live RLS" is determined: This page reads RLS from the Base44 SDK by calling entity.schema() for each entity and using schema.rls. RLS is enforced on the Base44 backend (server-side); the app cannot bypass it. The SDK may not expose RLS in the schema response, so "Live" can show "No RLS" even when the backend does enforce rules. Use "Refresh live RLS" after changing RLS in the Base44 dashboard; if it still looks wrong, the platform may not return RLS in the schema API.
Some entities missing "organizationId"
Toggles apply to all entities. Updates descriptions below.
| Role | create | read | update | delete |
|---|---|---|---|---|
| Admin | ||||
| User |
Based on the Role Matrix (recommended). Each entity card shows Live RLS (actual Base44) vs Recommended.
Read = see cards. Create = add card. Update = edit/move. Delete = remove card.
Read = see boards. Create = new board. Update = rename/reorder. Delete = remove board.
Read = see messages. Create = send. Update = edit (if supported). Delete = clear/remove.
Read = see alerts. Create = raise alert. Update = acknowledge. Delete = dismiss.
Read = see activity. Create = log activity. Update/Delete = usually restricted.
Read = see workstations and choose one. Create = seed defaults. Update = rename/claim. Delete = reset.
Read = see compliance data. Create/Update = write. Delete = purge.
Read = see labels. Create/Update = manage labels. Delete = remove label.
Read = see rules. Create/Update/Delete = configure rules.
Read = see profile. Update = edit (usually admin).
Read = see game. Create = new game. Update = move/inputs. Delete = end game.
Read = view audit log. Create = app writes only. Update/Delete = typically denied.
Read = see scores. Create = submit score.
Simulate allowed/denied based on current Role Matrix (no live API).
Expand any entity card above and use "Show RLS JSON" to copy create/read/update/delete rules for Base44.
Rules are generated from the tenant field and Role Matrix. Each entity card shows the same pattern; copy the JSON you need from the entity that matches your Base44 entity name.