Rules on source tables flow to Models, Answers, Liveboards, and Spotter responses. ThoughtSpot uses rule-based RLS with the system variables ts_groups and ts_username. Looker enforces RLS in LookML with access_filter (map a user attribute to a field and filter every query) and sql_always_where (inject a WHERE clause into every SQL statement from an Explore). Copilot answers inherit the user’s RLS role, but Copilot itself requires Fabric capacity rather than a Pro license alone.
For embedded analytics, the embed session sets the attributes, so each customer sees only their rows without a separate workbook per tenant. Sigma resolves user attributes and functions such as CurrentUserEmail() and CurrentUserAttributeText() at query time and pushes the resulting WHERE clause to the warehouse (Snowflake, BigQuery, Databricks, Redshift, or PostgreSQL). These four use the same underlying idea, user attributes that resolve at query time into SQL filters, and differ in how the attribute is defined and how it reaches an embedded session. Dynamic RLS is the right default for anything beyond a handful of roles. A PostgreSQL policy takes a database administrator and a migration, but it also protects the same table from every other tool that sets the same context.
The table compares nine platforms on the attributes that decide an RLS evaluation. Row-level security filters query results based on the authenticated user before data reaches a chart, dashboard, export, or AI answer. Pricing was re-verified against each vendor’s public pricing page in September 2026.
When any user runs a query, Basedash sets a PostgreSQL session variable, basedash.groups, to the comma-separated list of groups that user belongs to in the workspace. The weakness is maintenance, since sandboxes are saved queries rather than declarative filters. The filter is part of the same version-controlled semantic layer that Lightdash’s AI agents query. Because workbooks and AI queries resolve through that model, the filter applies to ad hoc exploration and to embedded dashboards where the embed session sets the attributes. Omni defines access filters on user attributes in its shared model, the governed layer that sits between the raw Unli Slots Casino schema and workbooks. Spotter is not included on the entry $25 per user per month tier; the $50 tier includes 25 Spotter queries per user per month.