## What happened

**Task:** <!-- e.g., "Set up MFA on patient records" -->

**Skill said:** <!-- e.g., "Use auth.jwt()->'app_metadata' in the RLS policy" -->

**Expected:** <!-- e.g., "The function also needs SECURITY DEFINER + grant to supabase_auth_admin" -->

## Source

**File:** <!-- e.g., references/security-model.md -->

**Section:** <!-- e.g., "Trust Boundaries > user_metadata vs app_metadata" -->

## Fix suggestion

<!-- Leave blank if unsure -->
