# Help planning out access & authorisation

**URL:** <https://community.glideapps.com/t/help-planning-out-access-authorisation/68946>\
**Category:** Ask for Help\
**Created:** [December 22, 2023, 4:44pm UTC](https://community.glideapps.com/t/help-planning-out-access-authorisation/68946 "2023-12-22T16:44:52Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![sumgii](https://avatars.discourse-cdn.com/v4/letter/s/e0b2c6/32.png) [@sumgii](https://community.glideapps.com/u/sumgii)\
**Post date:** [December 22, 2023, 4:44pm UTC](https://community.glideapps.com/t/help-planning-out-access-authorisation/68946/1 "2023-12-22T16:44:52Z")

</div>

I’ve just finished the University lessons on row-owners and roles and I’m still not sure how to apply this to my use-case (not that I am trying to do anything particularly complex). Anyone up for giving me some input on this.

I am building a tool to help manage the work I do with client businesses. I use it to record meetings, actions etc and the clients also log in to update progress, share more information etc:

- Two types of user (Lets call them Advisor & Client)
- Advisor can see / edit anything.
- Clients relate to a company: Can be multiple users per company
- Clients can only ever see data relating to the company they are part of
- This all needs to be reasonably secure, not just in source but hidden from view.

What I was trying to do:

- Restrict to users in users table only
- Have company id column as role
- Add company ID to all sensitive rows (pretty much everything).

I feel like I have missed a step though. This doesn’t seem to work. No user can see anything. I also don’t know how to deal with the advisor role using that method.

Any thoughts or advice?

---

<div class="post-metadata">

**Author:** ![Darren\_Murphy](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/darren_murphy/32/47326_2.png) [@Darren\_Murphy](https://community.glideapps.com/u/Darren_Murphy)\
**Post date:** [December 22, 2023, 5:16pm UTC](https://community.glideapps.com/t/help-planning-out-access-authorisation/68946/2 "2023-12-22T17:16:14Z")

</div>

You are on the right track, just missing a few details. Here are a few pointers:

- Make sure you have a Role column (Text type) in your User Profiles table, and it is set as the Role in your User Profiles configuration.
- Each of your Advisors should have an “Advisor” role
- Each of your Clients should have their CompanyID as a role
- Now in each of your tables where you want to protect data, you will need two (Text type) columns with Row Owners applied:  
– The first column should have the word “Advisor”, so that your Advisors get access. Obviously you’ll want this in every row  
– The second column should have the CompanyID of the Company that each row is associated with.

The above is basically all you need.

---

<div class="post-metadata">

**Author:** ![sumgii](https://avatars.discourse-cdn.com/v4/letter/s/e0b2c6/32.png) [@sumgii](https://community.glideapps.com/u/sumgii)\
**Post date:** [December 22, 2023, 8:33pm UTC](https://community.glideapps.com/t/help-planning-out-access-authorisation/68946/3 "2023-12-22T20:33:57Z")

</div>

Aaaahhhhh… Makes sense. Thanks. I’ll give this a go shortly.

---

<div class="post-metadata">

**Author:** ![sumgii](https://avatars.discourse-cdn.com/v4/letter/s/e0b2c6/32.png) [@sumgii](https://community.glideapps.com/u/sumgii)\
**Post date:** [December 23, 2023, 5:53pm UTC](https://community.glideapps.com/t/help-planning-out-access-authorisation/68946/4 "2023-12-23T17:53:07Z")

</div>

Quick update on this:

Good news : Works perfectly. Thanks - That would have taken me a long time to work out.

Bad news : I’m now in trouble at home because I’m itching to update the whole app to do this an I am apparently supposed to be wrapping christmas presents.

---

<div class="post-metadata">

**Author:** ![system](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/system/32/53398_2.png) [@system](https://community.glideapps.com/u/system)\
**Post date:** [December 30, 2023, 5:53pm UTC](https://community.glideapps.com/t/help-planning-out-access-authorisation/68946/5 "2023-12-30T17:53:55Z")

</div>

This topic was automatically closed 7 days after the last reply. New replies are no longer allowed.
