# Permissions - Add to Entity based on Related Entity

**URL:** https://community.fibery.io/t/permissions-add-to-entity-based-on-related-entity/859
**Category:** Ideas & Features
**Created:** [July 26, 2020, 5:42pm UTC](https://community.fibery.io/t/permissions-add-to-entity-based-on-related-entity/859 "2020-07-26T17:42:28Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![B\_Sp](https://avatars.discourse-cdn.com/v4/letter/b/e8c25b/32.png) [@B\_Sp](https://community.fibery.io/u/B_Sp)
#### Post date: [July 26, 2020, 5:42pm UTC](https://community.fibery.io/t/permissions-add-to-entity-based-on-related-entity/859/1 "2020-07-26T17:42:28Z")

</div>

Hi guys,

I wanted to make the specific request for **A related entity picking up the permissions of the related entity**

There are probably many aspects of this, as entities can get related at various moments in Fibery:

- Creating a new Entity within another Entity’s “details” card

- Creating an entity from “Scratch,” say in a table within its own Type in its App

I wanted to focus on the first example, **Creating a related entity from an Entity Card**

My team really uses this feature a lot. In particular, when you create an Entity from a Rich Text field, and it’s auto-related into the Connections section. This is currently only available on One-to-Many relations. It would be great if when that happens, these newly related “children” Entities inherit the permission of the “Parent” where the new Entity is created.

One use of this would be Time Tracking: If you have a large time tracking Type, like shown here:

> [@Time estimation and tracking?](https://community.fibery.io/t/time-estimation-and-tracking/106/2):
>
> And this is how formula works
> 
> ![](https://us1.discourse-cdn.com/flex020/uploads/fibery/original/2X/8/83f1e21b3906d6190d5a63d67c906e9ab1ea8c6a.jpeg)
> 
> [Total time spent formula](https://www.youtube.com/watch?v=CqFRJ27Btg4)
> 
> Time list inside Task should be improved to display more info. It will be done in future. I just show how it can work.

You would be able to have each Time Tracking Entity with permission only of the “Parent” entity in which time is tracked. So if your Financial officer is working on some sensitive info, that time tracked won’t be visible to a contractor on a month-to-month agreement, who’s also in the same Time Tracking Type.

This would imply that within a Type, Entities can have various permission levels, which is being worked on per these related requests:

> [@Permissions on entity viewed across apps](https://community.fibery.io/t/permissions-on-entity-viewed-across-apps/421):
>
> Hi, I am going to set up Fibery to represent work of my entire Start-Up, which is in the software development space. I intend to have an entity called “task” which will represent work across apps - for developers, such as “update version of Php,” and, for example, for marketing such as “complete the new copy on marketing Email.” There may also be some executive-level tasks such as “set up interview for latest job candidate.” I plan to have all the tasks originate in one app. However, will I …

[https://community.fibery.io/t/entity-level-permissions/117](https://community.fibery.io/t/entity-level-permissions/117)

Hope that’s something you guys are thinking about, thanks!

---

<div class="post-metadata">

### Author: ![B\_Sp](https://avatars.discourse-cdn.com/v4/letter/b/e8c25b/32.png) [@B\_Sp](https://community.fibery.io/u/B_Sp)
#### Post date: [November 12, 2020, 5:53pm UTC](https://community.fibery.io/t/permissions-add-to-entity-based-on-related-entity/859/2 "2020-11-12T17:53:56Z")

</div>

Hi again,

I’d be grateful if anybody could help me with this one based on today’s release here:

> [@CHANGELOG: November 12 / True "No Access" permissions, Jira integration](https://community.fibery.io/t/changelog-november-12-true-no-access-permissions-jira-integration/1160/1):
>
> ## 💪 True “No Access” permissions
> 
> In Fibery you can restrict access to Apps. Previously a user with no access to an App saw an awful lot of sensitive data, like names of all entities. Name was a public attribute visible to all people, even without any access. It appeared this decision was not correct and it took us a couple of months to solve it. The only thing that remains visible is entity Id, and it does not contain any information.
> 
> For example, a user has access to Employees but has no access to Salaries. Salaries are connected to Employee, but this information will be hidden from a user.
> 
> It all means you can safely use Fibery for sensitive data and be sure that restricted entities will not be visible anywhere (UI, Search results, API, etc).
> 
> Now we can move to functional permissions improvements, like simplify permissions management, add read-only users, and implement entity-level access.

I am trying to set up Time Tracking based on some Team Fibery suggestions I quoted above, and the new article [here.](https://blog.fibery.io/time-tracking/). My big question is can I have an App for Time Tracking. The Type in question will be “Time Entries.” I’d like to relate this to any number of other Types. **All** users will have access to this “Time Entry” type. But the types that will be related to will have limited access, for example some Finance or Executive-level stuff. So all of the team will be tracking time in this one “Time Entry” Type. But I’d like to limit the ability for some users with limited permissions to see _all_ related entities, because some of those they won’t have access to.

Hope that makes sense and glad for any guidance out there. I’m hoping this is also a use case for many who are trying to track time in Fibery!

---

<div class="post-metadata">

### Author: ![Polina\_Zenevich](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/polina_zenevich/32/480_2.png) [@Polina\_Zenevich](https://community.fibery.io/u/Polina_Zenevich)
#### Post date: [November 13, 2020, 11:32am UTC](https://community.fibery.io/t/permissions-add-to-entity-based-on-related-entity/859/3 "2020-11-13T11:32:35Z")

</div>

Hi!  
Soon we will release a cool article specially for the Time Tracking issue 🙂  
And of course, you can create an App for Time Tracking. But permissions are still on the same level - per App - not per Type, not per View, not per Entity.  
For now at least.  
So currently you can’t limit permissions per Entity.
