Review row-level security policies. Use when adding Supabase/Postgres RLS, changing auth policies, reviewing tenant/user isolation, or checking whether service-role functions safely bypass normal user access.