# \[DONE\] Entity-level permissions

**URL:** https://community.fibery.io/t/done-entity-level-permissions/2163
**Category:** Ideas & Features
**Tags:** permissions, sharing
**Created:** [October 29, 2021, 2:32pm UTC](https://community.fibery.io/t/done-entity-level-permissions/2163 "2021-10-29T14:32:55Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![antoniokov](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/antoniokov/32/201_2.png) [@antoniokov](https://community.fibery.io/u/antoniokov)
#### Post date: [October 29, 2021, 2:32pm UTC](https://community.fibery.io/t/done-entity-level-permissions/2163/1 "2021-10-29T14:32:56Z")

</div>

## Why?

So far all the [access management](https://help.fibery.io/en/articles/5350066-permissions) in Fibery happens on the App level. The only way to share an individual Entity (ex. a Task) with a teammate is via read-only [external sharing](https://help.fibery.io/en/articles/5303654-sharing-entities-and-documents) 💩

 ![image](https://us1.discourse-cdn.com/flex020/uploads/fibery/original/2X/4/4aa252302d28b34ae05d5eb0191d6c97c49e99db.png)

Introducing Entity-level permissions will unlock new opportunities:

### Collaborating with clients

As we’ve learned, Fibery is a surprisingly good fit for many service companies: think digital agencies and development studios.

A good fit, that is to say, before we start talking about access management. Creating an App (or a Workspace 😬) per client is a workaround for the most desperate. Most just say “screw it” and we can’t blame them.

Being able to share a Project with the client would be a game-changer.

### Aligning departments around a product/objective/etc.

Some huge endeavors require all departments to chip in. This means the relevant knowledge is scattered across different Apps.

 ![image](https://us1.discourse-cdn.com/flex020/uploads/fibery/original/2X/7/7cc8c2796b4ac79fb51d35abe1c7375b791fa593.png)

Sharing _everything_ inside a Product, Objective, or Initiative would facilitate cross-functional collaboration™ (buy our book on successful enterprise success®).

### ~~Solving climate change~~

Delegating tasks to contractors, splitting CRM among sales folks — the list goes on…

Also, based on how Fibery works under the hood, we need some form of Entity-level permissions to build [My Space](https://community.fibery.io/t/private-area-my-space-where-i-can-create-views-and-docs-visible-to-myself-only/1365), [Read-only users](https://community.fibery.io/t/approved-read-only-guest-users/1527), and collaborative external sharing.

## How?

🤨 You might ask: if they are so important, why ~~the fu~~ Entity-level permissions haven’t been implemented yet?

Well, they are extremely hard to get right — even conceptually, without thinking about UI and implementation. Hopefully, we think we have a decent model. Here it is.

### Sharing a single Entity

There are 4 default levels of access (the same is in Notion, what a coincidence):

- Can View
- Can Comment
- Can Edit
- Full Access

Those with Full Access are free to share an Entity with an individual User or a Group by picking one of these levels.

All Entity “companions” are shared automatically with the same level: Files, Documents, Whiteboards, etc.

### Sharing Entity and its children

To share a Project and all its Tasks (and their Subtasks), we need some kind of inheritance.

Fibery [knows better than vertical hierarchy](https://fibery.io/blog/the-knowledge-organization/) distinguishing between one/many — one/many relations and making things difficult for permissions 🥴.

Hopefully, these sensible defaults will work for most scenarios:

 ![image](https://us1.discourse-cdn.com/flex020/uploads/fibery/original/2X/7/7f5fec4fda77853c45e8c7e6ebafdcfa4fe6dc4b.png)

Here is how they look in a ~~real~~ fictional Workpsace:

 ![image](https://us1.discourse-cdn.com/flex020/uploads/fibery/original/2X/6/6a8a5677626fa48fa2e813086fe93b0af19db18f.png)

A person with Full Access to a particular Objective will have the same access to its Key Results, Ideas, Features, and Stories.

### Defining custom access templates

Default access levels and inheritance rules work for most but not all scenarios. That’s why Creators are free to define their own custom access templates for a particular Type.

For example, here’s `Client` access template for `Customer` Type:

 ![image](https://us1.discourse-cdn.com/flex020/uploads/fibery/original/2X/7/776df583bbca79a61aa351dd1f53b1683218c060.png)

It allows to automatically give a client’s manager access to all the Projects and Stories but not to Contacts (hiding cheeky notes) or Tasks (avoiding micromanagement).

## What’s next

✨ For the most curious readers, here is the entire new access model in its spectacular boring glory: [Permissions United](https://the.fibery.io/Product_Management/Product_Area/96/5350?sharing-key=b6ef0956-35dd-41db-ac03-e9e9bad33c30).

**We would love to hear your feedback!** Specifically, two kinds of it:

1. 💎 _“Looks great! You haven’t even mentioned this scenario but it’s gonna work: to share my dog’s resume, I’d create a new access template…”_
2. 💩 _“Complicated and doesn’t solve my case: we have 1408 clients communicating with us through a psychic…”_

Please share your cases here or, if you prefer some privacy, via Intercom.

---

<div class="post-metadata">

### Author: ![Mikhail\_Anfimau](https://avatars.discourse-cdn.com/v4/letter/m/f04885/32.png) [@Mikhail\_Anfimau](https://community.fibery.io/u/Mikhail_Anfimau)
#### Post date: [March 6, 2019, 12:58pm UTC](https://community.fibery.io/t/done-entity-level-permissions/2163/2 "2019-03-06T12:58:33Z")

</div>

I’m certainly missing a possibility to limit user access to a particular entity.

Some examples:

- a user can see releases, features, stories and bugs only from those projects, assigned to the user’s team  
or
- I’d like to have multi-organization setup and have no concerns, that users will see goals or product plans not owned by his organization
- while keeping task app for everyone, I’d like to create a subset exclusively for myself
- I’d like to be able to limit visibility of certain entities to certain subsets of users
- I’d like to create private boards for experimenting

Thanks a lot!

---

<div class="post-metadata">

### Author: ![rickcogley](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/rickcogley/32/274_2.png) [@rickcogley](https://community.fibery.io/u/rickcogley)
#### Post date: [August 24, 2019, 1:06pm UTC](https://community.fibery.io/t/done-entity-level-permissions/2163/3 "2019-08-24T13:06:37Z")

</div>

Yes to this. As of 24 Aug 2019 the permissions are app level only. That means, I can assign users to either see or not see an app. What I need is, for instance, if I make a folder in the wiki, I want to make that read only for most of the team, except for a couple people. I would use this for documents that should not be edited by just anyone, that the company is legally required to maintain and make available, like “rules of employment”.

---

<div class="post-metadata">

### Author: ![alex.mart](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/alex.mart/32/247_2.png) [@alex.mart](https://community.fibery.io/u/alex.mart)
#### Post date: [November 14, 2019, 6:37pm UTC](https://community.fibery.io/t/done-entity-level-permissions/2163/4 "2019-11-14T18:37:54Z")

</div>

@mdubakov, Interested in how close the implementation of this feature is planned in the roadmap? It is very important feature for our team. It is second priority after [UI feedback speed](https://community.fibery.io/t/ui-feedback-speed-with-drag-and-drop-in-board-view-is-to-slowly/401) for our needs.

By the way, where can I see the current roadmap?  
Maybe you should consider writing a roadmap on a published Fibery board?

---

<div class="post-metadata">

### Author: ![mdubakov](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/mdubakov/32/10_2.png) [@mdubakov](https://community.fibery.io/u/mdubakov)
#### Post date: [November 14, 2019, 6:46pm UTC](https://community.fibery.io/t/done-entity-level-permissions/2163/5 "2019-11-14T18:46:00Z")

</div>

We don’t have a roadmap right now, since public release will definitely affect it and change all the plans. Most likely it will appear near Jan. It means Entity-level permissions schedule is unclear at this moment.

---

<div class="post-metadata">

### Author: ![Christoph\_Lange](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/christoph_lange/32/329_2.png) [@Christoph\_Lange](https://community.fibery.io/u/Christoph_Lange)
#### Post date: [November 27, 2019, 11:09am UTC](https://community.fibery.io/t/done-entity-level-permissions/2163/6 "2019-11-27T11:09:40Z")

</div>

+1 here. Would need entity level permissions to map sensitive processes like 1:1s, performance and salary reviews.

---

<div class="post-metadata">

### Author: ![julian](https://avatars.discourse-cdn.com/v4/letter/j/74df32/32.png) [@julian](https://community.fibery.io/u/julian)
#### Post date: [May 19, 2020, 1:39pm UTC](https://community.fibery.io/t/done-entity-level-permissions/2163/7 "2020-05-19T13:39:58Z")

</div>

Updates on this?? It’s a big reason my team is skeptical.

---

<div class="post-metadata">

### Author: ![B\_Sp](https://avatars.discourse-cdn.com/v4/letter/b/e8c25b/32.png) [@B\_Sp](https://community.fibery.io/u/B_Sp)
#### Post date: [May 19, 2020, 5:09pm UTC](https://community.fibery.io/t/done-entity-level-permissions/2163/8 "2020-05-19T17:09:43Z")

</div>

Hey Guys, I don’t mean to pile on but since we have some activity here from @julian, I would like to add my vote. I would be happy with Type-level permissions if that was easier. Ultimately, Entity-level is superior.

Just for some context, I really like apps like Wrike, Asana, ClickUp, and some others that will add you as a share/viewer when you comment @ a particular user.

I would also love to see this feature come along at a similar time:

> [@\[DONE\] "Watcher" of an Entity](https://community.fibery.io/t/watcher-of-an-entity-use-the-assignement-extension/563):
>
> Hi guys, I was interested in creating the equivalent functionality of “watcher” that is offered by a lot of PM apps around their tasks and entities. This is a user who is “subscribed” to an entity’s activity - so they are informed when any status changes, fields are adjusted, comments are made, and so forth. Can I use the “assignment” extension to create this functionality? Or would I need to do this another way if that extension needs to be reserved for only actual assignees? Thanks guys!

Thanks guys and keep up the great work!

---

<div class="post-metadata">

### Author: ![mikael](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/mikael/32/887_2.png) [@mikael](https://community.fibery.io/u/mikael)
#### Post date: [August 12, 2020, 3:07pm UTC](https://community.fibery.io/t/done-entity-level-permissions/2163/9 "2020-08-12T15:07:35Z")

</div>

+1 on this.

My use case is as a product lead for many products (aka sites) of our web agency. I’d like to create “spaces” for each product utilizing the same setup of entities. Whenever I try to create entity relations it should only show entities within the “space”. I tried to implement a setup like this and almost made but it failed on the fact that I can’t filter available entities during lookup when creating a relationship.

 ![Skärmavbild 2020-08-12 kl. 17.05.04](https://us1.discourse-cdn.com/flex020/uploads/fibery/original/2X/5/539e79d641cbdb8d995819810c7e0cf4211830f9.png)

---

<div class="post-metadata">

### Author: ![Chr1sG](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/chr1sg/32/3941_2.png) [@Chr1sG](https://community.fibery.io/u/Chr1sG)
#### Post date: [August 13, 2020, 8:25am UTC](https://community.fibery.io/t/done-entity-level-permissions/2163/10 "2020-08-13T08:25:31Z")

</div>

I just thought I would add in my use case for entity permissions and that is a role-based implementation, i.e. a user has one or more roles, and it is the roles that determine the access levels on an entity (or at least app-level) basis. I don’t need to figure out which apps a user should have access to, I just assign them to the necessary roles.  
It’s obviously very analogous to traditional file permissions based on user groups.  
[I think I’ve mentioned it to the fibery team directly, but I’m adding it here to open up the discussion]

@mikael Your need seems to maybe relate to filtering and views combined. Were you aware that you can use filters in formula fields to return linked entities based on the filter criteria? I think combining suitable lookups/filters with the various views available in fibery, you might be able to achieve what you have in mind (assuming I’ve correctly understood where you’re coming from).  
It’s not clear to me whether permissions is really what you need…

---

<div class="post-metadata">

### Author: ![mdubakov](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/mdubakov/32/10_2.png) [@mdubakov](https://community.fibery.io/u/mdubakov)
#### Post date: [August 17, 2020, 9:38am UTC](https://community.fibery.io/t/done-entity-level-permissions/2163/11 "2020-08-17T09:38:35Z")

</div>

We are working on permissions and will not stop till entity-level permissions are implemented. However, it might take 4-6 months to get there.

---

<div class="post-metadata">

### Author: ![Chr1sG](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/chr1sg/32/3941_2.png) [@Chr1sG](https://community.fibery.io/u/Chr1sG)
#### Post date: [August 17, 2020, 2:12pm UTC](https://community.fibery.io/t/done-entity-level-permissions/2163/12 "2020-08-17T14:12:01Z")

</div>

Great to know the time horizon. Rome wasn’t built in a day! 🙂

---

<div class="post-metadata">

### Author: ![B\_Sp](https://avatars.discourse-cdn.com/v4/letter/b/e8c25b/32.png) [@B\_Sp](https://community.fibery.io/u/B_Sp)
#### Post date: [September 29, 2020, 4:48pm UTC](https://community.fibery.io/t/done-entity-level-permissions/2163/13 "2020-09-29T16:48:00Z")

</div>

Michael, it was good to hear from you re: permissions, would be curious if you could shed any light on whether you guys will also be looking at Type-level:

> [@Type-level permissions](https://community.fibery.io/t/type-level-permissions/501):
>
> Hi guys, I know this is something you are thinking about, but I wanted to add the request here as a sort of “upvote” to make a case to prioritize this. Here is my situation and why this would be useful: I am trying to set up all all “work items” in my team (small software development with some marketing, HR, content, etc.) can be tracked in one place. So stuff like development chores, recruiting tasks, recurring posting of blog articles each week, etc. These are all “work items,” and not “t…

Many of the tools I’ve used have nice ways to handle these levels of permissions. One of my favorite, which is central in Wrike, and Asana, and ClickUp - who I might loosely consider a similar “triumvirate” of “Task Managers” like Airtable/Coda/Notion is within the “nocode” sub-space, all do this:

- If you @mention a user within a comment stream, they get added **just to that particular task**

- You can “share” lists/folders/projects to a particular group.

So in the case of Fibery, I think you have a great chance with your existing hierarchy to do a similar approach that would be very familiar to those coming in from these tools - and perhaps others who handle things similarly like Hive, Monday, Teamwork Projects, etc.

So in Fibery this would work out as:

- You can access particular users to a Type, much as you do now with a whole App

- via mentioning a user, they get access to an **individual** Entity only.

The addition of the Type-level permission makes it easier to break down groups of Entities within an App. I have this need in Task Management I am running in Fibery, where I have groups of Tasks in Types that I’d like to have only certain users see, and not the whole App’s worth of Types.

Hope that’s useful and curious to see how you guys will solve this!

---

<div class="post-metadata">

### Author: ![mikael](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/mikael/32/887_2.png) [@mikael](https://community.fibery.io/u/mikael)
#### Post date: [September 9, 2021, 1:09pm UTC](https://community.fibery.io/t/done-entity-level-permissions/2163/14 "2021-09-09T13:09:25Z")

</div>

Any updates on this topic. We are still longing for a solution on the use case of inviting a user to a specific entity and the user will then have access and be able to collaborate on all related children entites in an parent-child relationship.

---

<div class="post-metadata">

### Author: ![antoniokov](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/antoniokov/32/201_2.png) [@antoniokov](https://community.fibery.io/u/antoniokov)
#### Post date: [September 10, 2021, 5:03pm UTC](https://community.fibery.io/t/done-entity-level-permissions/2163/15 "2021-09-10T17:03:26Z")

</div>

Entity-level permissions the #1 customer request for us so we are committed to delivering a solution. The problem is quite challenging, both in terms of UX and technical solution — we are still in the preliminary design phase.

Once we have something “feedbackable”, I’ll be happy to share it with the community. In the best-case scenario, the beta will start the upcoming winter.

---

<div class="post-metadata">

### Author: ![Louis-FelixBorealys](https://avatars.discourse-cdn.com/v4/letter/l/58956e/32.png) [@Louis-FelixBorealys](https://community.fibery.io/u/Louis-FelixBorealys)
#### Post date: [March 25, 2022, 6:25pm UTC](https://community.fibery.io/t/done-entity-level-permissions/2163/16 "2022-03-25T18:25:41Z")

</div>

Hey! Just wanna know if there is any advancement on this? I have a client who is waiting for that. 🙂

---

<div class="post-metadata">

### Author: ![mdubakov](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/mdubakov/32/10_2.png) [@mdubakov](https://community.fibery.io/u/mdubakov)
#### Post date: [March 29, 2022, 5:52pm UTC](https://community.fibery.io/t/done-entity-level-permissions/2163/17 "2022-03-29T17:52:06Z")

</div>

Unfortunately implementation is not started yet, but we hope to start it in April.

---

<div class="post-metadata">

### Author: ![t.s](https://avatars.discourse-cdn.com/v4/letter/t/bcef8e/32.png) [@t.s](https://community.fibery.io/u/t.s)
#### Post date: [April 12, 2022, 9:32pm UTC](https://community.fibery.io/t/done-entity-level-permissions/2163/18 "2022-04-12T21:32:26Z")

</div>

What is the ETA on this? This is the only functionality stopping us from moving to Fibery from coda / notion / clickup / airtable.

---

<div class="post-metadata">

### Author: ![mdubakov](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/mdubakov/32/10_2.png) [@mdubakov](https://community.fibery.io/u/mdubakov)
#### Post date: [April 13, 2022, 7:02am UTC](https://community.fibery.io/t/done-entity-level-permissions/2163/19 "2022-04-13T07:02:53Z")

</div>

Still not started. Still want to start it in 1-2 weeks.

---

<div class="post-metadata">

### Author: ![New\_Turok](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/new_turok/32/1689_2.png) [@New\_Turok](https://community.fibery.io/u/New_Turok)
#### Post date: [April 28, 2022, 7:42pm UTC](https://community.fibery.io/t/done-entity-level-permissions/2163/20 "2022-04-28T19:42:57Z")

</div>

Permission rules as they are realized at GRIST are the most expected realization for me  
[https://support.getgrist.com/access-rules/](https://support.getgrist.com/access-rules/)

[Next page](https://community.fibery.io/t/done-entity-level-permissions/2163.md?page=2)
