Row & Column-Level Security
Restricting slices of a table rather than the whole table, and where it is enforced.
5 to work through
-
advanced
A data platform must enforce that analysts see only permitted rows and columns across thousands of tables and hundreds of users. How should this be designed so it is enforceable and auditable?
2 min answer -
advanced
A financial platform must restrict which rows and columns each analyst can see. Where should that be enforced?
2 min answer -
advanced
Design field-level and record-level access controls for a business application where each customer configures their own rules.
1 min answer -
advanced
Row-level security on the orders table restricts each regional analyst to their own region. An audit shows a Berlin analyst's dashboard returning French rows. The policy is present and correct on the table, the analyst's attributes are right, and the query in the dashboard selects from `orders_summary`. What happened?
3 min answer -
advanced
Salesforce's published Force.com design keeps many customers' records in shared tables described by metadata, rather than giving each tenant its own schema. Weissman and Bobrowski's SIGMOD 2009 paper describes the platform supporting tens of thousands of organisations this way. What does that choice force about access control, and where would copying it be a mistake?
2 min answer
3 terms in this topic
Policy Bypass Surface
The set of objects and paths through which data protected by a row or column policy can be read without that policy being evaluated - typically deriv…
patternPredicate-Based Filtering
A policy that appends a filter to every query on a table based on who is asking, so one physical table serves many audiences safely.
patternRow-Level Security
Access control enforced by the data platform on which rows a given principal can see, rather than by each application or query.
Neighbouring topics
Data Governance & Semantics
General material on ownership, meaning, quality and control of data at enterprise scale.
Data Mesh
Domain ownership, data as a product, self-serve platform, and federated governance.
Data Products
A dataset with an owner, an interface, an SLO, and consumers who can rely on it.
Data Contracts
Producers committing to schema, semantics and freshness, and breaking builds when they do not.
Data Catalog
Discovery, ownership and technical metadata, and why catalogues go stale.
Business Glossary
Agreeing what a term means before arguing about which number is right.
Semantic Layer
Metric definitions held once and served to every tool that asks.
Master Data Management
One authoritative record for a customer or product across systems that each have their own.
Reference Data
Code lists, hierarchies and currencies — small, shared, and quietly load-bearing.
Data Quality Dimensions
Completeness, accuracy, timeliness, consistency, validity and uniqueness as testable claims.
Data Observability
Freshness, volume, schema and distribution monitoring for pipelines that fail silently.
Data Stewardship
The operating model that makes ownership a role rather than a slide.
Data Access Models
Role, attribute and purpose-based access over analytical data, and how they compose.
Tokenisation & Masking
Dynamic masking, deterministic tokens, and preserving joinability without exposure.
Retention & Purge
Deleting from an append-only estate, and proving the deletion happened.
Data Sharing & Clean Rooms
Collaborating on data neither party may hand over, with computation as the interface.
Sensitivity Labelling
Propagating a classification through joins and derived tables so controls follow the data.
BI Governance
Dashboard sprawl, certified reports, and the number the board is allowed to see.
Self-Service vs Governed
Letting analysts move fast without four teams reporting four different revenues.