What is field-level security?
Field-level security is the fine-grained layer of permissions: control not just which records a user sees, but which fields within them.
It lets you share a record broadly while keeping specific sensitive fields visible only to the roles that need them.
Short answer
Field-level security controls access to individual fields, so a user might see a record but not certain sensitive fields on it - like margin, personal data, or internal notes. It provides finer control than record-level access, letting you expose most of a record while protecting specific fields. Field-level security is how sensitive data stays hidden from users who should not see it.
Key takeaways
- Controls access to individual fields, not just records.
- Hides sensitive fields while exposing the rest of a record.
- Finer-grained than record-level access.
- Protects data like margin, personal info, and internal notes.
Why it matters
Some fields are sensitive even on records people should otherwise see - cost and margin, personal data, internal-only notes. Field-level security protects exactly those fields without hiding the whole record, giving precise control where record-level access is too blunt.
How Ardovo handles it
Ardovo supports field-level security so sensitive fields are visible only to authorized roles, even on widely-shared records. Rook flags fields exposed more broadly than their sensitivity warrants, so protection is precise rather than all-or-nothing at the record level.
Frequently asked questions
What is the difference between field-level and record-level security?
Record-level security controls which records a user can access at all. Field-level security controls which fields within a record they can see or edit. Field-level is finer-grained, letting you expose most of a record while hiding specific sensitive fields from users who should not see them.
What fields need field-level security?
Sensitive ones users might otherwise see on records they access: cost and margin figures, personal or regulated data, internal-only notes, and compensation details. Field-level security protects exactly these while keeping the rest of the record visible, which record-level access cannot do.
Why use field-level security?
Because record-level access is sometimes too blunt - you want people to see a record but not certain fields on it. Field-level security gives precise control, protecting sensitive fields like margin or personal data without hiding the whole record, so people get the access they need and no more.