RowShield
Guides

Slack alerts for RLS changes: contents, thresholds, cadence

An alert nobody reads protects nothing, and alerts nobody can silence get muted within a week. RowShield's Slack destination is built around both facts: messages render as Block Kit attachments that survive skimming, each destination carries its own severity threshold, and delivery fires on transitions — created, regressed, resolved — rather than on every scan.

Slack delivery is a shipped feature, available from the Indie plan upward; Free projects receive HTML email. This page describes what arrives, how thresholds route findings, and the behaviours that keep the channel credible — and states plainly what remains manual on your side.

RowShield does not detect this yet. This guide gives you the catalog queries to check it yourself. The nine rules that do ship are listed on the rules index.

What arrives in Slack

Finding alerts carry the essentials: project, rule, severity, the affected table or bucket, a plain-language rationale, and the generated remediation SQL — built from your actual columns, owner-scoped, FORCE ROW LEVEL SECURITY included. Nothing sensitive rides along: leaked data appears as column names and counts, keys as fingerprints, never values.

Drift and lifecycle events use the same visual language. Schema drift reports what appeared, came back or disappeared since the previous scan; finding records report created, regressed or resolved. Because vocabulary is stable across destinations, a channel archiving months of alerts reads back as a chronological account of the project's posture.

Thresholds, per destination

Each destination carries its own severity threshold, which is the routing mechanism: email might receive everything while Slack receives critical and high only, or a second Slack channel reserved for critical alone. Thresholds belong to the destination, not the project, so routing changes never touch scan configuration.

Plan entitlements set which destinations exist: email alerts on Free, Slack added on Indie, Discord embeds and custom webhooks additionally on Team, with Growth quoted individually above that. Scan cadence scales alongside — daily, hourly, then every fifteen minutes. Rates are on the pricing page rather than restated here.

Why transitions only

Constant-state alerting trains people to ignore channels: the same finding re-posted hourly becomes wallpaper, and the day it matters, it is scrolled past. RowShield alerts on state changes instead — a finding posts when created, posts again if it regresses after a fix, and posts once more resolved.

Idempotence backs this up at the infrastructure layer: retried or repeated scans emit nothing new while state is unchanged, so a transient failure cannot manufacture a duplicate alert, and a project sitting in a broken state pages exactly once rather than once per cycle. The absence of messages becomes meaningful — silence means the last known state held.

Setup, and what stays manual

Connecting a channel happens in project settings and takes minutes; webhook URLs are stored masked, and log scrubbing applies throughout. Stated plainly, the manual remainder is judgement: choosing thresholds that fit the team, deciding who acts on which severity, and treating the remediation SQL as a reviewed proposal rather than an auto-applied patch. RowShield automates detection and delivery, never the decisions.

See the live behaviour on your own project rather than taking the format on faith: connect it for scheduled scans and watch a transition arrive, or start with the free audit at rowshield.dev/audit — a project URL is the entire input there.

Frequently asked

Which plans include Slack alert delivery?
Slack is included from Indie upward — three projects with hourly scans — while Free sends HTML email. Team adds Discord embeds and custom webhooks; Growth is quoted individually above that. Rates are on the pricing page.
Will Slack alerts repeat for the same finding?
No. Alerts fire on transitions — created, regressed, resolved — and retried scans emit nothing while state is unchanged. A finding that persists silently occupies its place in the dashboard instead of re-paging the channel.
Can different destinations receive different severities?
Yes — every destination carries its own severity threshold. A common arrangement sends everything to email, critical and high to a team channel, and critical alone to an on-call channel, all without touching scan configuration.

Check your project in about ten seconds

Paste a URL. No signup, no writes, nothing stored.

Run the free audit
supabase rls slack alertsslack security alerts postgresrls change notifications slackdatabase drift slack alert