# Field-level permissions

**URL:** <https://community.fibery.io/t/field-level-permissions/2799>\
**Category:** Ideas & Features\
**Created:** [May 13, 2022, 8:21pm UTC](https://community.fibery.io/t/field-level-permissions/2799 "2022-05-13T20:21:48Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Matt\_Blais](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/matt_blais/32/1464_2.png) [@Matt\_Blais](https://community.fibery.io/u/Matt_Blais)\
**Post date:** [May 13, 2022, 8:21pm UTC](https://community.fibery.io/t/field-level-permissions/2799/1 "2022-05-13T20:21:48Z")

</div>

Problem: Some fields within an entity may need different permissions than others.

E.g., if a Task has a “Due Date” field, this ideally would not be editable by the Assignee - only by a “manager”. But the Assignee will have Editor permission for most everything else in the Task.

A hack might be to use a lookup to a Due Date field that exists elsewhere, but that complicates changing the Due Date for someone who does have permission.

---

<div class="post-metadata">

**Author:** ![Chr1sG](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/chr1sg/32/3941_2.png) [@Chr1sG](https://community.fibery.io/u/Chr1sG)\
**Post date:** [May 14, 2022, 8:39am UTC](https://community.fibery.io/t/field-level-permissions/2799/2 "2022-05-14T08:39:30Z")

</div>

I don’t know when (if ever) field-level permissions might be implemented, but in the meantime, you might consider having an automation that notifies the manager when the Due Date field is updated, so at least he/she can be warned that someone is making changes.  
(and the change can be reverted if necessary)

---

<div class="post-metadata">

**Author:** ![Wilco\_Boode](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/wilco_boode/32/9985_2.png) [@Wilco\_Boode](https://community.fibery.io/u/Wilco_Boode)\
**Post date:** [February 21, 2025, 7:55am UTC](https://community.fibery.io/t/field-level-permissions/2799/3 "2025-02-21T07:55:42Z")

</div>

Hi,

We have several databases where we would like to limit visibility to some of our users (in this case our interns and externals who have access to our documentation)… Currently the only solution I see is to create a separate database, however I wondered if there is any option to provide access on a field level.

I’d imagine that by default the fields of an entity would be available based on the entity sharing settings. However, if I have a field ( for example prices of something) that I want to hide for everyone but our managers, then it would be nice to have a “Sharing” option where we can limit access to a set of users or a team/group.

---

<div class="post-metadata">

**Author:** ![Chr1sG](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/chr1sg/32/3941_2.png) [@Chr1sG](https://community.fibery.io/u/Chr1sG)\
**Post date:** [February 21, 2025, 8:08am UTC](https://community.fibery.io/t/field-level-permissions/2799/4 "2025-02-21T08:08:19Z")

</div>

Field level permissions are not on the radar any time soon

---

<div class="post-metadata">

**Author:** ![Yuri\_BC](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/yuri_bc/32/8803_2.png) [@Yuri\_BC](https://community.fibery.io/u/Yuri_BC)\
**Post date:** [February 21, 2025, 11:23am UTC](https://community.fibery.io/t/field-level-permissions/2799/5 "2025-02-21T11:23:05Z")

</div>

> [@Matt\_Blais](#):
>
> A hack might be to use a lookup to a Due Date field that exists elsewhere, but that complicates changing the Due Date for someone who does have permission.

You alread know this but just for people who may read this… When you update a field in Fibery it runs in a system mode that doesn’t record who made the change.  
A clumsy workaround is to use a submit button that captures an ‘input date’ field value and uses your identity to update a secure date field, if permitted.  
I hope that in the future Fibery automatically tags each update with the user’s info, e.g. through a property args.updatedBy

---

<div class="post-metadata">

**Author:** ![Chr1sG](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/chr1sg/32/3941_2.png) [@Chr1sG](https://community.fibery.io/u/Chr1sG)\
**Post date:** [February 21, 2025, 11:28am UTC](https://community.fibery.io/t/field-level-permissions/2799/6 "2025-02-21T11:28:15Z")

</div>

> [@Yuri\_BC](#):
>
> When you update a field in Fibery it runs in a system mode that doesn’t record who made the change

What do you mean by this?  
The activity log (for the workspace and for each entity) records whoever updates a field.

---

<div class="post-metadata">

**Author:** ![Yuri\_BC](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/yuri_bc/32/8803_2.png) [@Yuri\_BC](https://community.fibery.io/u/Yuri_BC)\
**Post date:** [February 21, 2025, 11:45am UTC](https://community.fibery.io/t/field-level-permissions/2799/7 "2025-02-21T11:45:51Z")

</div>

> [@Chr1sG](#):
>
> The activity log (for the workspace and for each entity) records whoever updates a field.

yes, but Fibery does not currently expose this user context directly in field-change automations, right?

---

<div class="post-metadata">

**Author:** ![Chr1sG](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/chr1sg/32/3941_2.png) [@Chr1sG](https://community.fibery.io/u/Chr1sG)\
**Post date:** [February 21, 2025, 12:02pm UTC](https://community.fibery.io/t/field-level-permissions/2799/8 "2025-02-21T12:02:35Z")

</div>

> [@Yuri\_BC](#):
>
> yes, but Fibery does not currently expose this user context directly in field-change automations, right?

true, but how does that relate to the text you quoted:

> [@Matt\_Blais](#):
>
> A hack might be to use a lookup to a Due Date field that exists elsewhere, but that complicates changing the Due Date for someone who does have permission.

?

Or were you referring to this:

> [@Chr1sG](#):
>
> having an automation that notifies the manager when the Due Date field is updated, so at least he/she can be warned that someone is making changes

?

---

<div class="post-metadata">

**Author:** ![Yuri\_BC](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/yuri_bc/32/8803_2.png) [@Yuri\_BC](https://community.fibery.io/u/Yuri_BC)\
**Post date:** [February 21, 2025, 12:28pm UTC](https://community.fibery.io/t/field-level-permissions/2799/9 "2025-02-21T12:28:58Z")

</div>

It applies to both your and his messages.  
Matt says a lookup field to field elsewhere complicates changing the Due Date for someone who does have permission.  
You suggested a notification when the field is updated.

The complication is that without user context any corrections or restrictions need to happen after the event.

I gave an extra workaround with an input field plus a secure field, and a button to expose the current user to an automation which either shows or submits.

---

<div class="post-metadata">

**Author:** ![Chr1sG](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/chr1sg/32/3941_2.png) [@Chr1sG](https://community.fibery.io/u/Chr1sG)\
**Post date:** [February 21, 2025, 12:38pm UTC](https://community.fibery.io/t/field-level-permissions/2799/10 "2025-02-21T12:38:08Z")

</div>

Then I don’t understand what the problem is.  
If you have an automation that notifies someone when a field is changed, it is possible to get the identity of the person who made the change using a formula: `User who triggered rule`

 ![image](https://us1.discourse-cdn.com/flex020/uploads/fibery/original/2X/5/536c4e4eea2f059050f0aff058ba4d64a2eee1af.png)

(and similar is available in buttons: `User who clicked button`)

Isn’t this exactly what you are asking for:

> [@Yuri\_BC](#):
>
> I hope that in the future Fibery automatically tags each update with the user’s info

?

Maybe I am misunderstanding your point 🤷

---

<div class="post-metadata">

**Author:** ![Yuri\_BC](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/yuri_bc/32/8803_2.png) [@Yuri\_BC](https://community.fibery.io/u/Yuri_BC)\
**Post date:** [February 21, 2025, 1:02pm UTC](https://community.fibery.io/t/field-level-permissions/2799/11 "2025-02-21T13:02:27Z")

</div>

Wow thats amazing, thank you for pointing that out.  
I will test it now…

---

<div class="post-metadata">

**Author:** ![mdubakov](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/mdubakov/32/10_2.png) [@mdubakov](https://community.fibery.io/u/mdubakov)\
**Post date:** [January 22, 2026, 3:33pm UTC](https://community.fibery.io/t/field-level-permissions/2799/12 "2026-01-22T15:33:43Z")

</div>

Now you can try to use Validation Rules to solve many of such cases

> [@January 22, 2026 / 🎛️ Architect mode, many AI and validation rules improvements](https://community.fibery.io/t/january-22-2026-architect-mode-many-ai-and-validation-rules-improvements/10284):
>
> control_knobs Architect vs. User modes Today we’re introducing a new way to keep Fibery calm and safe for everyday work: Architect vs. User modes. Admins and Architects can now switch between two modes: User mode: a cleaner, focused interface for daily work. Advanced controls are hidden: no accidental field edits, no surprise layout changes, fewer dangerous actions like Delete Relation Field in your face. Architect mode: the full power view for workspace design. Architect mode can be …
