# Permissions - entities vs views

**URL:** <https://community.fibery.io/t/permissions-entities-vs-views/1868>\
**Category:** Ideas & Features\
**Tags:** permissions\
**Created:** [August 3, 2021, 9:46am UTC](https://community.fibery.io/t/permissions-entities-vs-views/1868 "2021-08-03T09:46:17Z")\
**Posts on this page:** 17\
**Page:** 2

<div class="post-metadata">

**Author:** ![mgiammarco](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/mgiammarco/32/4033_2.png) [@mgiammarco](https://community.fibery.io/u/mgiammarco)\
**Post date:** [September 29, 2021, 6:50am UTC](https://community.fibery.io/t/permissions-entities-vs-views/1868/21 "2021-09-29T06:50:04Z")

</div>

> [@Chr1sG](#):
>
> It’s far from ideal, but until the new permissions model is rolled, out, it is the only way, unless **maybe you can live with people having view but not edit access for entities they are not assigned to?**

Absolutely not these are different customers and they must not see products of competitors.  
It is a so common case that I wonder why it is not supported from the beginning: as a software house I have several customers each one with its Scrum. I manage all the scrum but the customers stakeholder can create stories and see development progress. They cannot see stories of a different customer.

---

<div class="post-metadata">

**Author:** ![Chr1sG](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/chr1sg/32/3941_2.png) [@Chr1sG](https://community.fibery.io/u/Chr1sG)\
**Post date:** [September 29, 2021, 7:26am UTC](https://community.fibery.io/t/permissions-entities-vs-views/1868/22 "2021-09-29T07:26:39Z")

</div>

Then you would have to use separate apps for each customer.

---

<div class="post-metadata">

**Author:** ![Matt\_Blais](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/matt_blais/32/1464_2.png) [@Matt\_Blais](https://community.fibery.io/u/Matt_Blais)\
**Post date:** [September 29, 2021, 6:19pm UTC](https://community.fibery.io/t/permissions-entities-vs-views/1868/23 "2021-09-29T18:19:41Z")

</div>

I assume this limitation will be addressed by the planned per-entity permission model?

---

<div class="post-metadata">

**Author:** ![Chr1sG](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/chr1sg/32/3941_2.png) [@Chr1sG](https://community.fibery.io/u/Chr1sG)\
**Post date:** [September 29, 2021, 6:21pm UTC](https://community.fibery.io/t/permissions-entities-vs-views/1868/24 "2021-09-29T18:21:52Z")

</div>

That’s the plan 😁

---

<div class="post-metadata">

**Author:** ![Matt\_Blais](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/matt_blais/32/1464_2.png) [@Matt\_Blais](https://community.fibery.io/u/Matt_Blais)\
**Post date:** [October 1, 2021, 4:48pm UTC](https://community.fibery.io/t/permissions-entities-vs-views/1868/25 "2021-10-01T16:48:17Z")

</div>

Is there even a vague estimate of when **Entity-Level Permissions** might be implemented?

It is a necessary feature for my use case (and many others).

---

<div class="post-metadata">

**Author:** ![Matt\_Blais](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/matt_blais/32/1464_2.png) [@Matt\_Blais](https://community.fibery.io/u/Matt_Blais)\
**Post date:** [October 1, 2021, 5:21pm UTC](https://community.fibery.io/t/permissions-entities-vs-views/1868/26 "2021-10-01T17:21:46Z")

</div>

> [@Chr1sG](#):
>
> Then you would have to use separate apps for each customer.

If our goal is to limit “Customer” user access (today) to specific “Product” entities, is this a viable workaround:

- Create a separate “Customer Xyz” App for each customer, which we will try to use to allow specific user (Customer) access to only specific Products.
- Customers have no permission to access to the Products App, which contains the real Products Type.
- Create a separate “Customer Xyz Product” Type in the “Customer Xyz” App. Customer Xyz can access this App, so they can see these entities - but what are they?? We want to somehow link them to our “real” Product entities…
- For each “real” Product entity that we want to grant access to _Customer Xyz_, we create a “mirror” or “shadow” entity of “Customer Xyz Product” Type, in “Customer Xyz” App, and it must somehow reference the actual Product entity.
- Hopefully Customer Xyz still cannot see the “real” Product entity; but can they see its _fields_ via a Lookup field in “Customer Xyz Product” Type? How about Formula fields - can they see a Formula field in “Customer Xyz Product” Type that references data of the forbidden Product Type?

---

<div class="post-metadata">

**Author:** ![Chr1sG](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/chr1sg/32/3941_2.png) [@Chr1sG](https://community.fibery.io/u/Chr1sG)\
**Post date:** [October 5, 2021, 11:43am UTC](https://community.fibery.io/t/permissions-entities-vs-views/1868/27 "2021-10-05T11:43:12Z")

</div>

> [@Matt\_Blais](#):
>
> is this a viable workaround

It certainly is a viable workaround, and it might even be possible to make it less labour intensive with some automations (like, create a ‘shadow product’ every time a product is assigned to a particular customer).

However, assuming that your intention was merely to create a read-only version, then depending on how many entities you need to share, it might be just as easy to provide sharing links for the customer.

![image](https://us1.discourse-cdn.com/flex020/uploads/fibery/original/2X/5/56b7ca6bbfa0a0b6bb7bf3bddbc132cce607aa1b.png)

---

<div class="post-metadata">

**Author:** ![antoniokov](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/antoniokov/32/201_2.png) [@antoniokov](https://community.fibery.io/u/antoniokov)\
**Post date:** [October 9, 2021, 4:15pm UTC](https://community.fibery.io/t/permissions-entities-vs-views/1868/28 "2021-10-09T16:15:30Z")

</div>

> [@Matt\_Blais](#):
>
> Is there even a vague estimate of when **Entity-Level Permissions** might be implemented?

Still too early for any estimates but we are working on the unified model of permissions (including Entity-level) right now. We’ll share a very long and boring doc in the upcoming weeks.

---

<div class="post-metadata">

**Author:** ![Eren\_Turgut](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/eren_turgut/32/4425_2.png) [@Eren\_Turgut](https://community.fibery.io/u/Eren_Turgut)\
**Post date:** [March 24, 2022, 10:46am UTC](https://community.fibery.io/t/permissions-entities-vs-views/1868/29 "2022-03-24T10:46:44Z")

</div>

I would like to inquire about the status of this, as this is basically breaking our use case for Fibery.

Two examples:

- I can’t share my meeting notes of a meeting without sharing the notes of all meetings
- I can’t assign someone to see and review an entity without him being able to see all entities of said type.
- … (in an efficient and convenient way, I know I could create many spaces, but that kind of defeats the purpose)

Being able to share a view of a space without sharing the space itself would seemingly solve this problem:  
If I could:

1. create a view, filter it for employee XY, choose which fields are visible
2. then FIX that view such that it cannot be changed by whoever it is shared with
3. then assign groups or people to that particular view with access and edit rights ON A FIELD BASIS (e.g. Person A can edit field nr. 4, or even better, Person A can change field nr. 4 from A to B, but not from A to C)
4. at last, hide that view from my own dashboard i.e. like you can hide and show fields within entitites

That would bring Fibery to a whole different dimension my opinion, where views could act as apps, especially considering Fibery is working on multiple views being able to be embedded into a single view (if I understand correctly).

I also like your idea of permission dimension for Button pressing.

Of course I don’t know about the technical limitations of all this… it would be good to know whether this is possible and planned in the near future. As powerful as Fibery is, you simply cannot use it if there are confidentiality problems that come with it.

In a nutshell, the problem goes beyond entity level permissions, because currently it comes with view permission for everything, which is not very practical.

---

<div class="post-metadata">

**Author:** ![Chr1sG](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/chr1sg/32/3941_2.png) [@Chr1sG](https://community.fibery.io/u/Chr1sG)\
**Post date:** [March 24, 2022, 4:11pm UTC](https://community.fibery.io/t/permissions-entities-vs-views/1868/30 "2022-03-24T16:11:47Z")

</div>

> [@Eren\_Turgut](#):
>
> 1. create a view, filter it for employee XY, choose which fields are visible
> 2. then FIX that view such that it cannot be changed by whoever it is shared with
> 3. then assign groups or people to that particular view with access and edit rights ON A FIELD BASIS (e.g. Person A can edit field nr. 4, or even better, Person A can change field nr. 4 from A to B, but not from A to C)
> 4. at last, hide that view from my own dashboard i.e. like you can hide and show fields within entitites

1. possible

2. possible

3. not possible.  
you can set permissions for some users to be able view (but not configure) a particular space (and thus its views), and for some users to configure a space (and its views), but configuration at the field level is not possible. I do not anticipate field level access control will be coming any time soon.

4. if you’re an Admin, nothing can be hidden from you(!)  
Not sure what you mean by dashboard. We are working on ‘[My Space](https://community.fibery.io/t/in-dev-private-area-my-space-where-i-can-create-views-and-docs-visible-to-myself-only/1365)’ which would allow users to create views that only they can see (but this would probably conflict with the access permissions model for #3).  
Otherwise, for normal users, a space (and therefore its views) can be totally hidden if that is necessary.

---

<div class="post-metadata">

**Author:** ![Eren\_Turgut](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/eren_turgut/32/4425_2.png) [@Eren\_Turgut](https://community.fibery.io/u/Eren_Turgut)\
**Post date:** [March 24, 2022, 4:27pm UTC](https://community.fibery.io/t/permissions-entities-vs-views/1868/31 "2022-03-24T16:27:28Z")

</div>

Thanks for your reply.

Point 3 is not a necessity, but 1 and 2 are only possible on the condition that whoever you share the view with can see ALL the information within the same space, right?  
Being able to share and give access to specific things without giving view-rights to the whole space is a necessity in my opinion…

For example, in Space A, Database of Projects, I want to assign Project A to Person A, Project B to Person B, without Person A knowing Project B exists and vice versa.  
Another example: I can do contract management including filing on Fibery. However, if I want to assign specific contracts to specific people for them to be able to see the status etc., currently, I would need to give them view rights to all contracts.

I really would need to know whether this will be addressed in the near future.

To 4.: I mean the left sidepanel, where all the spaces and views are listed. If I create a fixed “view” as part of a process workflow for other people that I personally don’t need in that exact view, I might want it hidden from my view, maybe within a “hidden views” folder or just have a “show hidden views” slider or something. I hope it’s understandable what I mean.

---

<div class="post-metadata">

**Author:** ![Lug-gl](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/lug-gl/32/5293_2.png) [@Lug-gl](https://community.fibery.io/u/Lug-gl)\
**Post date:** [August 17, 2022, 8:47am UTC](https://community.fibery.io/t/permissions-entities-vs-views/1868/32 "2022-08-17T08:47:29Z")

</div>

> [@Chr1sG](#):
>
> a user who can edit entities assigned to him/her but cannot view any other entities

I’m searching for a functionality like this too. I think it’s really important for finance or 1:1 meetings.

Are there already some implementation plans?  
Do you’ve got a workaround for this?

---

<div class="post-metadata">

**Author:** ![mdubakov](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/mdubakov/32/10_2.png) [@mdubakov](https://community.fibery.io/u/mdubakov)\
**Post date:** [August 17, 2022, 9:22am UTC](https://community.fibery.io/t/permissions-entities-vs-views/1868/33 "2022-08-17T09:22:02Z")

</div>

This is in plans and we call it Entity-level permissions. We are going to start implementation soon. You can check some details here.

> [@\[DONE\] Entity-level permissions](https://community.fibery.io/t/planned-entity-level-permissions/2163):
>
> Why? So far all the [access management](https://help.fibery.io/en/articles/5350066-permissions) in Fibery happens on the App level. The only way to share an individual Entity (ex. a Task) with a teammate is via read-only [external sharing](https://help.fibery.io/en/articles/5303654-sharing-entities-and-documents) poop Introducing Entity-level permissions will unlock new opportunities: Collaborating with clients As we’ve learned, Fibery is a surprisingly good fit for many service companies: think digital agencies and development studios. A good fit, that is to say, before we start talking about access management. …

---

<div class="post-metadata">

**Author:** ![Pawel\_Maksymczak](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/pawel_maksymczak/32/5896_2.png) [@Pawel\_Maksymczak](https://community.fibery.io/u/Pawel_Maksymczak)\
**Post date:** [December 6, 2022, 8:07pm UTC](https://community.fibery.io/t/permissions-entities-vs-views/1868/34 "2022-12-06T20:07:03Z")

</div>

Hi, what you mean by soon ?

---

<div class="post-metadata">

**Author:** ![mdubakov](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/mdubakov/32/10_2.png) [@mdubakov](https://community.fibery.io/u/mdubakov)\
**Post date:** [December 6, 2022, 8:26pm UTC](https://community.fibery.io/t/permissions-entities-vs-views/1868/35 "2022-12-06T20:26:28Z")

</div>

We are close to starting, tech research is almost over! This is the hardest thing we ever planned, so no promises anymore 🙂

---

<div class="post-metadata">

**Author:** ![Pawel\_Maksymczak](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/pawel_maksymczak/32/5896_2.png) [@Pawel\_Maksymczak](https://community.fibery.io/u/Pawel_Maksymczak)\
**Post date:** [December 6, 2022, 8:47pm UTC](https://community.fibery.io/t/permissions-entities-vs-views/1868/36 "2022-12-06T20:47:17Z")

</div>

Hi Mikhail , permissions to view entities is crucial for teams bigger than small companies.  
I am trying now to implement HR system prototype on fibery. With view permissions on entity level could make fibery a permanent solution with many users. Without it i’ll have to look for dedicated solution. Can you please provide rough estimation when it may be available ?

---

<div class="post-metadata">

**Author:** ![mdubakov](https://sea2.discourse-cdn.com/flex020/user_avatar/community.fibery.io/mdubakov/32/10_2.png) [@mdubakov](https://community.fibery.io/u/mdubakov)\
**Post date:** [December 7, 2022, 7:44am UTC](https://community.fibery.io/t/permissions-entities-vs-views/1868/37 "2022-12-07T07:44:50Z")

</div>

I did that several times in the past and always failed, so I am not gonna repeat this mistake again. My best guess is 2023 so far, when we will have less uncertainty I will post more details here.

[Previous page](https://community.fibery.io/t/permissions-entities-vs-views/1868.md?page=1)
