Strong post — RLS is the right answer for exactly the reason you give. Three production gotchas worth adding: (1) RLS doesn't apply to table owners or superusers, so the app role must not own the tables, and watch out for BYPASSRLS; (2) the tenant context (e.g. SET app.current_tenant) must be reset per checkout when you're behind PgBouncer — a leaked tenant setting is a data leak; (3) policy expressions run on every row, so keep them sargable and index-friendly on large tables or RLS becomes a performance tax. Miss any of the three and the enforcement story quietly breaks.