What is field-level security?

Field-level security is the fine-grained layer of permissions: control not just which records a user sees, but which fields within them.

It lets you share a record broadly while keeping specific sensitive fields visible only to the roles that need them.

Short answer

Field-level security controls access to individual fields, so a user might see a record but not certain sensitive fields on it - like margin, personal data, or internal notes. It provides finer control than record-level access, letting you expose most of a record while protecting specific fields. Field-level security is how sensitive data stays hidden from users who should not see it.

Key takeaways

  • Controls access to individual fields, not just records.
  • Hides sensitive fields while exposing the rest of a record.
  • Finer-grained than record-level access.
  • Protects data like margin, personal info, and internal notes.

Why it matters

Some fields are sensitive even on records people should otherwise see - cost and margin, personal data, internal-only notes. Field-level security protects exactly those fields without hiding the whole record, giving precise control where record-level access is too blunt.

How Ardovo handles it

Ardovo supports field-level security so sensitive fields are visible only to authorized roles, even on widely-shared records. Rook flags fields exposed more broadly than their sensitivity warrants, so protection is precise rather than all-or-nothing at the record level.

Frequently asked questions

What is the difference between field-level and record-level security?

Record-level security controls which records a user can access at all. Field-level security controls which fields within a record they can see or edit. Field-level is finer-grained, letting you expose most of a record while hiding specific sensitive fields from users who should not see them.

What fields need field-level security?

Sensitive ones users might otherwise see on records they access: cost and margin figures, personal or regulated data, internal-only notes, and compensation details. Field-level security protects exactly these while keeping the rest of the record visible, which record-level access cannot do.

Why use field-level security?

Because record-level access is sometimes too blunt - you want people to see a record but not certain fields on it. Field-level security gives precise control, protecting sensitive fields like margin or personal data without hiding the whole record, so people get the access they need and no more.

Keep reading

Get started with Rally or browse all pages.