DOSSIERSEHPC-RBAC-RLS
github.com/east-highpeformance-hongkongDatabase-Level Zero-Trust Access Isolation
granular multi-role permissions using native PostgreSQL RLS
Published: 2026-06-20 | Project: East High Performance Centre | Discipline: Distributed Systems & High-Throughput State
Author: Nicholas Alexander MacAskill — Founder & CTO, Flocano Labs | Canonical: https://www.nicholasmacaskill.com/dossier/ehpc-rbac-rls
Policy validation latency
< 1.5ms
Verified Invariant
Access control failures
0
Verified Invariant
Access Control Isolation
The platform partitions operations across sys-admin, coach, parent, and player roles directly within the database layer using PostgreSQL Row-Level Security (RLS) policies. This ensures queries execute within safe transactional boundaries and prevents client-side state manipulation from compromising user profiles or operational records.
Security Policies
For the core coach_drills table, edit and deletion permissions are restricted to the owner of the resource or administrative roles:
SQLPRODUCTION RUNTIME
CREATE POLICY "Coaches and Admins can manage drills"
ON public.coach_drills
FOR ALL
USING (
auth.uid() = coach_id
OR EXISTS (
SELECT 1 FROM public.profiles
WHERE profiles.id = auth.uid()
AND profiles.role IN ('admin', 'sys-admin')
)
)
WITH CHECK (
auth.uid() = coach_id
OR EXISTS (
SELECT 1 FROM public.profiles
WHERE profiles.id = auth.uid()
AND profiles.role IN ('admin', 'sys-admin')
)
);