# Access template allowing related entity creation

**URL:** <https://community.fibery.io/t/access-template-allowing-related-entity-creation/6246>\
**Category:** Get Help\
**Created:** [May 31, 2024, 6:36am UTC](https://community.fibery.io/t/access-template-allowing-related-entity-creation/6246 "2024-05-31T06:36:09Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![BertrandC](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/bertrandc/32/4828_2.png) [@BertrandC](https://community.fibery.io/u/BertrandC)\
**Post date:** [May 31, 2024, 6:36am UTC](https://community.fibery.io/t/access-template-allowing-related-entity-creation/6246/1 "2024-05-31T06:36:09Z")

</div>

Hey there,

As what could happen often happen, here comes the moment where we would like to use the access template to grant permission to user to create a related entity.  
Here is an example of what we would like to do: we have 2 DBs (DB\_1 & DB\_2) with restricted access (as containing sensitive information), both being linked, and we do grant access to internal users to DB\_1 entities when needed and once shared, we would like the user to be able to create a new entry in DB\_2.  
With current access template capabilities, we can provide additional rights to associated entities, but we can’t grant creation right (thus, requires someone else with needed rights to do it on behalf of the actual user).  
As the [associated doc](https://the.fibery.io/@public/User_Guide/Guide/Custom-Access-Templates-240/anchor=Selecting-path-capabilities--6e478801-53d3-42c6-a8fa-f4710affa0bf) is suggesting to ask you whenever we do face such a situation, here comes the request 😉  
May you have some kinda workaround to allow such access right workflow?

Keep the spirit, cheers 🤘

---

<div class="post-metadata">

**Author:** ![antoniokov](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/antoniokov/32/201_2.png) [@antoniokov](https://community.fibery.io/u/antoniokov)\
**Post date:** [May 31, 2024, 12:59pm UTC](https://community.fibery.io/t/access-template-allowing-related-entity-creation/6246/2 "2024-05-31T12:59:43Z")

</div>

Hey!

A few quick questions before I jump to suggesting any solutions:

1. Should a user who created an Entity of DB\_2 be able to unlink it from its DB\_1 parent?
2. If yes, should the user retain access to the DB\_2 Entity once it’s unlinked from the parent?
3. In general, do you currently have “orphan” DB\_2 Entities not linked to any DB\_1 in your workspace? If yes, is this desired?

If you can deanonymize DB\_1 and DB\_2 that would be nice as well but I’ll understand if you want to keep the names private 🙂

---

<div class="post-metadata">

**Author:** ![BertrandC](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/bertrandc/32/4828_2.png) [@BertrandC](https://community.fibery.io/u/BertrandC)\
**Post date:** [June 3, 2024, 7:57am UTC](https://community.fibery.io/t/access-template-allowing-related-entity-creation/6246/3 "2024-06-03T07:57:30Z")

</div>

Hey,  
Thanks for the swift feedback, some answers below:

1. this is actually not an expected requirement for our use case, on a standard way of working, unlinking both entities should not happen
2. not expected does not mean it won’t happen, it’d actually make sense for the creator to keep the access to the created entity (but again, not a mandatory thing)
3. nope, we should not (thus point 1/, but may happen depending on point 2/)

DB names are the following (and may indeed help to understand the use case and the need to keep some privacy):

- DB\_1 = Position
- DB\_2 = Interview

Long story short, we do manage our hiring process through Fibery as follows:

- when needed/possible, we create a new _Position_ (aka DB\_1)
- we create an _Interview_ (aka DB\_2) to track output of our discussion

Not sure if it does change that much the solution you may have in mind, Interview name is generated through a formula (from linked position and candidate - which is another DB from the same Space).

---

<div class="post-metadata">

**Author:** ![antoniokov](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/antoniokov/32/201_2.png) [@antoniokov](https://community.fibery.io/u/antoniokov)\
**Post date:** [June 6, 2024, 4:01pm UTC](https://community.fibery.io/t/access-template-allowing-related-entity-creation/6246/4 "2024-06-06T16:01:17Z")

</div>

Thanks, it makes perfect sense now!

We don’t have creation rights as a part of custom access templates since there is currently no way to enforce a parent for a newly created Entity. This means you cannot grant permission to create Interviews for a certain Position — only to create Interviews in general.

To unlock your use case we are missing two things:

1. Specify who has the right to create Entities of a DB without granting read access to all the Entities of the DB.
2. Mark a certain relation as required and do not allow “orphans”.

The first part is planned for this year as a part of Database access. The second part is more tricky but, I assume, less pressing.

The current workarounds would be to use publicly shared [Forms](https://the.fibery.io/@public/User_Guide/Guide/Forms-134) to create Interviews or use [Contributor Space access](https://the.fibery.io/@public/User_Guide/Guide/Share-Space-232/anchor=Space-access-levels--5bec1ad4-0042-4fef-a803-84d53d240da3). Neither is great, I have to admit — that’s why we are working on DB permissions 👷‍♂️.
