Journey: RLS
Stage 3b of the guided journey. Install Row-Level Security policies for user-owned tables.
When to use
- Dispatched by
journeywhencurrent_stage: rls. - Directly via
/butterbase-skills:journey-rls. - Folded into
journey-schemawhenhackathon_mode: true(do not run separately).
Preflight
If docs/butterbase/03-preflight.md is missing, older than 24 hours, or 00-state.md has app_id: null, invoke butterbase-skills:journey-preflight first. Wait for it to return successfully before proceeding.
Inputs
docs/butterbase/02-plan.md— the RLS section.docs/butterbase/00-state.md— forapp_id.
Procedure
Refresh docs. Call
butterbase_docswithtopic: "auth". For RLS-specific patterns, also WebFetchhttps://docs.butterbase.ai/auth/rls. Skip if cache is fresh.Read the RLS section of
02-plan.md. Print it back:"About to install RLS policies: <list>. Proceed?". Wait foryes.Invoke
butterbase-skills:debug-rlsvia the Skill tool with modeproactive, passing the RLS plan andapp_id. For each user-isolation entry, the wrapped skill callsmanage_rls action: create_user_isolation. For custom policies,manage_rls action: enablethenaction: create_policy.After it returns, sanity-check with
manage_rls action: listand show the user.Append one line to
docs/butterbase/04-build-log.md:<ISO timestamp> rls manage_rls okTick
- [x] rlsin00-state.md, setcurrent_stage:to the next unchecked stage, bumplast_updated.Return to
journeyorchestrator (or ask"Continue to the next stage? (yes/no)").
Outputs
- Live RLS policies in the Butterbase app.
- One line in
04-build-log.md.
Anti-patterns
- ❌ Skipping
manage_rls action: listverification — invisible policy failures are the #1 RLS gotcha. - ❌ Creating policies on a table where RLS is not enabled —
enablemust come first.