Skip to main content
Version: Next

pg_policy

The catalog pg_policy stores row level security policies for tables. A policy includes the kind of command that it applies to (possibly all commands), the roles that it applies to, the expression to be added as a security-barrier qualification to queries that include the table, and the expression to be added as a WITH CHECK option for queries that attempt to add new records to the table.

columntypereferencesdescription
oidoidThe object ID
polnamenameThe name of the policy
polerelidoidpg_class.oidThe table to which the policy applies
polcmdcharThe command type to which the policy is applied: r for SELECT, a for INSERT, w for UPDATE, d for DELETE, or * for all
polpermissiveboolean Is the policy permissive or restrictive?
polrolesARRAYpg_authid.oid The roles to which the policy is applied
polqualpg_node_tree The expression tree to be added to the security barrier qualifications for queries that use the table
polwithcheckpg_node_tree The expression tree to be added to the WITH CHECK qualifications for queries that attempt to add rows to the table
note

Apache Cloudberry applies policies stored in pg_policy only when pg_class.relrowsecurity is set for their table.