Record-level access

Each model declares who owns its records, and each record is private or public. Sharing a private record with one named person is a grant, which you can revoke.

Who owns a record

A model's records belong to the project, to the signed-in user who created them, to the team member who created them, or to an organisation. Project ownership is the default and means no individual owner. You declare the owner in the model's access settings.

Private or public

A private record is readable by its owner and by anyone holding a grant. A public record is readable by anyone, including a request that carries only a public key. Private is the default, except for a project-owned model created without a setting, which starts public.

One record can be set either way from the Access tab of the record editor. It keeps that setting when the model's default later changes, and records that follow the default move with it when the change is published.

Sharing with a named person

A grant names one person, one record and one level: read, write or delete. The record stays private, and the grant can be revoked. The API generates grant and revoke calls for each model owned by a user or a team member, and the SDK has them as grantAccess and revokeAccess. Only someone who can edit a record may change its grants.

What a signed-in user reads

A query on a user-owned model takes no filter. With the user's token it returns that user's records and any granted to them. A secret key is the back-office view, and with the right scope it reads every owner's records.

Records a caller may not see

A record the caller cannot see comes back as null, the same answer as a record that does not exist. The rules are enforced in the database with row-level security. Files have access rules of their own and do not take on the visibility of a record that points at them.

Read the detail

The authorisation guide covers owners, visibility, grants and reads that follow a reference between records.