# Private Pro Role Security Query

**URL:** <https://community.glideapps.com/t/private-pro-role-security-query/23352>\
**Category:** Ask for Help\
**Created:** [February 24, 2021, 12:15pm UTC](https://community.glideapps.com/t/private-pro-role-security-query/23352 "2021-02-24T12:15:26Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![V88](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/v88/32/90054_2.png) [@V88](https://community.glideapps.com/u/V88)\
**Post date:** [February 24, 2021, 12:15pm UTC](https://community.glideapps.com/t/private-pro-role-security-query/23352/1 "2021-02-24T12:15:26Z")

</div>

I am experimenting with a **Private Pro** app for a customer. The User Profile table will contain rows for the customer’s **clients** and also the customer’s **staff** members.

The **clients** should only see their own rows whilst the **staff** members should see all rows. This logic applies to both the User Profile table and other tables within the app that relate to a client.

It seems as though I need a row owner to be both the **client** email and the **staff** role.

Question:

Is this best achieved via an array column (which I’d prefer NOT to do) or can I simply specify two columns as row owner in each table where this is applicable?

EDIT: Don’t think I mean array column, rather concatenated column

---

<div class="post-metadata">

**Author:** ![Darren\_Murphy](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/darren_murphy/32/47326_2.png) [@Darren\_Murphy](https://community.glideapps.com/u/Darren_Murphy)\
**Post date:** [February 24, 2021, 12:31pm UTC](https://community.glideapps.com/t/private-pro-role-security-query/23352/2 "2021-02-24T12:31:46Z")

</div>

I think there are a few different ways to skin this cat. Here is one way I’ve done it:

- In my User Profiles table:

- In other linked tables:

NB. I created the above before the new “multiple columns as owners” feature became available - I haven’t really explored that yet.

I know the above doesn’t help with your goal of avoiding array columns, but… what’s your objection to that?

Edit: Oops, upon examining my app a bit closer, I realised that I actually use an array column as Row Owner in my User Profiles sheet. Have updated the above to reflect that.

---

<div class="post-metadata">

**Author:** ![V88](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/v88/32/90054_2.png) [@V88](https://community.glideapps.com/u/V88)\
**Post date:** [February 24, 2021, 12:43pm UTC](https://community.glideapps.com/t/private-pro-role-security-query/23352/3 "2021-02-24T12:43:34Z")

</div>

Hey @Darren_Murphy thanks for the reply and nice to hear from you 🙂

Re: Array columns, I try to avoid them if possible because they can make my “logic” a bit funny by forcing me to name multiple columns in a certain way. I’d rather not ideally. That’s the only reason TBH.

Re: your comment about “multiple columns as owners” that would be perfect. Is that actually a thing now and, if so, is there an instructions link somewhere?

Finally, it seems that in exploring this functionality I have uncovered an issue in the (new) GDE. When I use a combination of email address and role as a row owner and then impersonate within the GDE as follows:

- Impersonate user 1 (has no role just email) - only see their rows - all good
- Impersonate user 2 (has no role just email) - only see their rows - all good
- Impersonate user 3 (has role and email) - see their rows AND rows owner by their role - all good

But, once I have impersonated user 3, their "view’ seems to stick within the GDE even when I go back to impersonate user 1 or user 2. Is this a know thing?

Sorry - two questions in there somewhere - cheers!

---

<div class="post-metadata">

**Author:** ![Darren\_Murphy](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/darren_murphy/32/47326_2.png) [@Darren\_Murphy](https://community.glideapps.com/u/Darren_Murphy)\
**Post date:** [February 24, 2021, 12:48pm UTC](https://community.glideapps.com/t/private-pro-role-security-query/23352/4 "2021-02-24T12:48:10Z")

</div>

> [@V88](#):
>
> Re: your comment about “multiple columns as owners” that would be perfect. Is that actually a thing now and, if so, is there an instructions link somewhere?

Sure is. Here is the announcement:

> [@Assign Multiple Row Owner Columns](https://community.glideapps.com/t/assign-multiple-row-owner-columns/22060):
>
> You can now assign multiple columns as Row Owner columns, including Array Columns. [Read more](https://docs.glideapps.com/all/reference/security-and-per-user-data/row-owners#multiple-row-owners)

> [@V88](#):
>
> But, once I have impersonated user 3, their "view’ seems to stick within the GDE even when I go back to impersonate user 1 or user 2. Is this a know thing?

I haven’t noticed that exact behaviour, but it certainly can be a bit quirky sometimes. Whenever I see weird stuff like that, I find that it (usually) sorts itself out if I navigate back to the main dashboard, and then open the app again.

---

<div class="post-metadata">

**Author:** ![V88](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/v88/32/90054_2.png) [@V88](https://community.glideapps.com/u/V88)\
**Post date:** [February 24, 2021, 1:19pm UTC](https://community.glideapps.com/t/private-pro-role-security-query/23352/5 "2021-02-24T13:19:45Z")

</div>

Appreciated @Darren_Murphy I must have missed that one. Cheers.

Re: the quirks, they can be “reset” by exiting and entering the GDE or by refreshing, but that whole process can make design / review / debug awkward. I imagine this would be super-confusing to a new user trying to get their head around row owners and roles.

Is this a logged issue @Mark or @Jason ?

---

<div class="post-metadata">

**Author:** ![eltintero](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/eltintero/32/76520_2.png) [@eltintero](https://community.glideapps.com/u/eltintero)\
**Post date:** [February 24, 2021, 3:14pm UTC](https://community.glideapps.com/t/private-pro-role-security-query/23352/6 "2021-02-24T15:14:59Z")

</div>

Hey! Please send us a recording and link to the app to [support@glideapps.com](mailto:support@glideapps.com)

---

<div class="post-metadata">

**Author:** ![Darren\_Murphy](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/darren_murphy/32/47326_2.png) [@Darren\_Murphy](https://community.glideapps.com/u/Darren_Murphy)\
**Post date:** [February 24, 2021, 3:51pm UTC](https://community.glideapps.com/t/private-pro-role-security-query/23352/7 "2021-02-24T15:51:11Z")

</div>

The issue described by @V88 is very easy to replicate, and it’s repeatable. I just tried on two different apps - one a Private Pro and the other a Legacy Pro - and both behaved the same. I’ll put together a video and send it through with a support link.

Edit: Have emailed support with details.

---

<div class="post-metadata">

**Author:** ![V88](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/v88/32/90054_2.png) [@V88](https://community.glideapps.com/u/V88)\
**Post date:** [February 24, 2021, 5:46pm UTC](https://community.glideapps.com/t/private-pro-role-security-query/23352/8 "2021-02-24T17:46:46Z")

</div>

Cheers @Darren_Murphy - I’ve been with a customer the last few hours so only just saw your response. I have repeated too. It’s a bit worrying given this is supposed to be a security feature. Can we give any priority to a response from support? Not necessarily an immediate fix but an acknowledgement that there’s an issue here?
