# Does a User's permissions affect Button script capabilities?

**URL:** <https://community.fibery.io/t/does-a-users-permissions-affect-button-script-capabilities/5044>\
**Category:** Get Help\
**Tags:** permissions\
**Created:** [August 30, 2023, 10:56pm UTC](https://community.fibery.io/t/does-a-users-permissions-affect-button-script-capabilities/5044 "2023-08-30T22:56:50Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Matt\_Blais](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/matt_blais/32/1464_2.png) [@Matt\_Blais](https://community.fibery.io/u/Matt_Blais)\
**Post date:** [August 30, 2023, 10:56pm UTC](https://community.fibery.io/t/does-a-users-permissions-affect-button-script-capabilities/5044/1 "2023-08-30T22:56:50Z")

</div>

**When a User runs a Button script, does the User’s permissions restrict what the script can do?**

_Scenario:_

A User has Editor access to the “Clients” DB, and the User runs a Button script from there.

This User does NOT have access to the “Secrets” DB, but the script calls `fibery.getEntityById()` to retrieve a record from the “Secrets” DB.

Does this API call succeed?

---

<div class="post-metadata">

**Author:** ![Chr1sG](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/chr1sg/32/3941_2.png) [@Chr1sG](https://community.fibery.io/u/Chr1sG)\
**Post date:** [August 31, 2023, 7:47am UTC](https://community.fibery.io/t/does-a-users-permissions-affect-button-script-capabilities/5044/2 "2023-08-31T07:47:08Z")

</div>

The script will be executed with the permission level of the person pressing the button (just like for any no-code action).  
However, the IDs of entities are considered public, even if the content of an entity is not, so in your example

> [@Matt\_Blais](#):
>
> the script calls `fibery.getEntityById()` to retrieve a record from the “Secrets” DB.  
> Does this API call succeed?

then the API call will ‘succeed’ but will not return any detail from the Secrets DB.
