Access rules

Control who can see which facts, rows and columns.

No one learns through Doram what they couldn't see in the source.

Access is controlled in three ways, each applied at one point:

RuleControlsApplied by
Role rulesWhich facts a person can seeThe retriever, before it searches
Row rulesWhich rows a person can seeThe compiler, inside the SQL, before anything is added up
Column rulesWhich values are hidden or maskedThe compiler

Because row rules sit inside the query, a total never includes rows the person isn't allowed to see. If an answer would need a hidden column, Doram refuses rather than reveal it.

Where rules come from

Rules are imported from your warehouse's own grants, or set by an admin in Settings → People → Access rules. When the two disagree, the stricter one wins. Grants are re-read on every schema scan, so a permission removed in the warehouse is removed in Doram too.

An access rule can cover a whole source, a table, a column or a document. Rules only ever narrow access. Anything a rule doesn't cover follows the person's role, and admins always keep access.

No agent can create or change an access rule.

On this page