RowShield

Help / Findings

Disputing a finding

All plansLast reviewed 2026-08-23

Findings are mechanical verdicts about a snapshot, and mechanisms can misread intent. When one does, we would rather hear about it than leave you arguing with a dashboard, and disputes have changed the engine before.

Before you write

Two checks settle most disagreements in seconds. First, the rule documentation linked from the finding states exactly what is detected and what is suppressed. Second, False positives we suppress lists the deliberate exclusions, so a service_role-scoped policy or a RESTRICTIVE tautology you can see in the catalog may already be accounted for.

Also check the finding is not simply stale: a scan from minutes before your migration landed explains most it-is-already-fixed cases, and Scan-now refreshes the picture immediately.

What happens next

Email info@getveristria.com with the project reference, the finding title, and one paragraph on why you believe it is wrong; a schema snippet helps and never hurts. An engineer re-reads your snapshot against the rule definition and replies with one of two things: the evidence that the finding stands, or agreement that it does not. Either way the reply quotes the relevant rule definition, so agreement and disagreement look equally concrete.

When a rule is wrong, the correction ships for everyone and stored snapshots are re-judged, so transitions and history stay truthful rather than being patched cosmetically. Disputes about wording or clarity are equally welcome and are treated the same way: read by a person, answered plainly, with the outcome recorded in the rule documentation. Marking the subject line with the rule slug, for example RLS_TAUTOLOGY, routes it fastest.

The same address serves product questions as well as disputes, and there is no separate premium lane: paying plans do not jump the queue because there is no queue to jump, just mail answered by the people who maintain the rules. If a dispute turns on how Supabase itself behaves rather than on our reading of it, the reply will say so and say what we checked.

Did this answer your question? If not, tell us what is missing — article corrections go straight to the person who maintains it.

RowShield checks 9 rule classes continuously. This article describes shipped behaviour only.