RLS5 — live RunView as a non-exempt user returns ONLY rows satisfying its RLS predicate.
The end-to-end proof (not just the fingerprint / predicate text): run a real, cache-bypassing
RunView as a discovered non-exempt user and assert no row carries another user's UserID.
Needs the single-user LivePair; skips-as-pass when every available user is RLS-exempt (admins).
RLS5 — live RunView as a non-exempt user returns ONLY rows satisfying its RLS predicate. The end-to-end proof (not just the fingerprint / predicate text): run a real, cache-bypassing RunView as a discovered non-exempt user and assert no row carries another user's UserID. Needs the single-user LivePair; skips-as-pass when every available user is RLS-exempt (admins).