# 🔒 Row Owners

**URL:** https://community.glideapps.com/t/row-owners/4927
**Category:** General
**Created:** [February 25, 2020, 6:29pm UTC](https://community.glideapps.com/t/row-owners/4927 "2020-02-25T18:29:12Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![Mark](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/mark/32/125_2.png) [@Mark](https://community.glideapps.com/u/Mark)
#### Post date: [February 25, 2020, 6:29pm UTC](https://community.glideapps.com/t/row-owners/4927/1 "2020-02-25T18:29:12Z")

</div>

We just rolled out a new security feature we call Row Owners. It will give your users more security and allows you to keep confidential data in Glide. If your users keep personal data in Glide, please use Row Owners:

> **[Glide Docs](https://www.glideapps.com/docs)**
>
> Welcome to Glide Docs, a steadily growing collection of articles and videos on how to use Glide. We can’t wait to see what you build!

If you want some more context, this has been discussed here on the forum:

> [@Row Level Security](https://community.glideapps.com/t/row-level-security/1761/4):
>
> It’s important to note that filtering by email will not give you real data security. All data is still downloaded to the app, and only filtered in the app. Somebody who knows what they’re doing can open the app in a web browser and get to all the other user’s data. We have been working on a feature to provide true row-level security, where the app can’t even download rows that the logged-in user doesn’t “own”. Let us know if you definitely need this feature and we can onboard you to the curr…

---

<div class="post-metadata">

### Author: ![George\_B](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/george_b/32/534_2.png) [@George\_B](https://community.glideapps.com/u/George_B)
#### Post date: [February 25, 2020, 6:37pm UTC](https://community.glideapps.com/t/row-owners/4927/2 "2020-02-25T18:37:48Z")

</div>

Since this data is coming from the Google sheet, I assume that the Google sheet can refer to this sheet via various copy row functions, and “copy” the data into another sheet, which the app could then access. Is that correct? I do understand that this is a layer of abstraction that the end user does not have any access to and fully under control of the developer.

---

<div class="post-metadata">

### Author: ![Mark](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/mark/32/125_2.png) [@Mark](https://community.glideapps.com/u/Mark)
#### Post date: [February 25, 2020, 6:43pm UTC](https://community.glideapps.com/t/row-owners/4927/3 "2020-02-25T18:43:19Z")

</div>

Yes, you could do that in the spreadsheet if you wanted some data that’s hidden via Row Owners to show somewhere else.

---

<div class="post-metadata">

### Author: ![George\_B](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/george_b/32/534_2.png) [@George\_B](https://community.glideapps.com/u/George_B)
#### Post date: [February 25, 2020, 6:44pm UTC](https://community.glideapps.com/t/row-owners/4927/4 "2020-02-25T18:44:32Z")

</div>

That is exactly what I was thinking about. Thanks.

---

<div class="post-metadata">

### Author: ![zzoldan](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/zzoldan/32/452_2.png) [@zzoldan](https://community.glideapps.com/u/zzoldan)
#### Post date: [February 25, 2020, 6:48pm UTC](https://community.glideapps.com/t/row-owners/4927/5 "2020-02-25T18:48:06Z")

</div>

Awesome! I’m excited to try this new feature.

Thanks for pushing a new update, again! 🙂

---

<div class="post-metadata">

### Author: ![Ken](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/ken/32/4483_2.png) [@Ken](https://community.glideapps.com/u/Ken)
#### Post date: [February 27, 2020, 3:45am UTC](https://community.glideapps.com/t/row-owners/4927/6 "2020-02-27T03:45:16Z")

</div>

Awesome update and glad to hear it is now rolled out widely!

---

<div class="post-metadata">

### Author: ![edbs\_India](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/edbs_india/32/4055_2.png) [@edbs\_India](https://community.glideapps.com/u/edbs_India)
#### Post date: [May 1, 2020, 3:55pm UTC](https://community.glideapps.com/t/row-owners/4927/8 "2020-05-01T15:55:02Z")

</div>

What is the status of this update ? Eagerly looking forward to see this.

---

<div class="post-metadata">

### Author: ![D\_J](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/d_j/32/6213_2.png) [@D\_J](https://community.glideapps.com/u/D_J)
#### Post date: [May 1, 2020, 3:58pm UTC](https://community.glideapps.com/t/row-owners/4927/9 "2020-05-01T15:58:53Z")

</div>

It’s out already. You can use it

---

<div class="post-metadata">

### Author: ![bryanrcosta](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/bryanrcosta/32/17191_2.png) [@bryanrcosta](https://community.glideapps.com/u/bryanrcosta)
#### Post date: [December 11, 2020, 2:22pm UTC](https://community.glideapps.com/t/row-owners/4927/10 "2020-12-11T14:22:29Z")

</div>

@Mark two points where I need some clarity

You mentioned:

> Somebody who knows what they’re doing can open the app in a web browser and get to all the other user’s data.

Is this data that only lives in the google spreadsheet or glide data editor as well (e.g: Template Columns, Math Columns, IF then else, Columns etc)?

> We have been working on a feature to provide true row-level security, where the app can’t even download rows that the logged-in user doesn’t “own”. Let us know if you definitely need this feature and we can onboard you to the current early version.

I’m interested in this, and would like to know more 🙂 Do I need to formulate my request in any way?

---

<div class="post-metadata">

### Author: ![V88](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/v88/32/90054_2.png) [@V88](https://community.glideapps.com/u/V88)
#### Post date: [December 11, 2020, 2:29pm UTC](https://community.glideapps.com/t/row-owners/4927/11 "2020-12-11T14:29:59Z")

</div>

Hi. I’ll try to give you a basic heads-up for starters. If a row in a sheet is not “protected” then you should assume that it could be accessed. This applies to all columns, both Google and Glide. It can be accessed because whilst you may not see it within the app, it may well have been downloaded to the browser and is only hidden. Therefore a “savvy” user could reveal the data using a number of different debugging tools.

To ensure that a row can only be accessed by a specific user (or users) then enable the Row Owner feature. That will ensure that the row cannot be accessed unless Row Owner matches (checkout the tutorial on this). It achieves this by not downloading the row to the browser, so it is not available even using debugging tools.

---

<div class="post-metadata">

### Author: ![bryanrcosta](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/bryanrcosta/32/17191_2.png) [@bryanrcosta](https://community.glideapps.com/u/bryanrcosta)
#### Post date: [December 11, 2020, 2:34pm UTC](https://community.glideapps.com/t/row-owners/4927/12 "2020-12-11T14:34:50Z")

</div>

Exactly what I assumed as well. Thanks for the valuable input 🙂

---

<div class="post-metadata">

### Author: ![Drearystate](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/drearystate/32/49605_2.png) [@Drearystate](https://community.glideapps.com/u/Drearystate)
#### Post date: [December 11, 2020, 2:46pm UTC](https://community.glideapps.com/t/row-owners/4927/13 "2020-12-11T14:46:58Z")

</div>

You pay for them to download less

---

<div class="post-metadata">

### Author: ![ehdubya](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/ehdubya/32/24087_2.png) [@ehdubya](https://community.glideapps.com/u/ehdubya)
#### Post date: [December 11, 2020, 3:02pm UTC](https://community.glideapps.com/t/row-owners/4927/14 "2020-12-11T15:02:10Z")

</div>

So…which column would be advisable to become the Row Owner? Row ID? Users sign-in email address?

Thanks.

---

<div class="post-metadata">

### Author: ![ThinhDinh](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/thinhdinh/32/49_2.png) [@ThinhDinh](https://community.glideapps.com/u/ThinhDinh)
#### Post date: [December 11, 2020, 3:05pm UTC](https://community.glideapps.com/t/row-owners/4927/15 "2020-12-11T15:05:22Z")

</div>

I believe in all of the cases I have to use row owners, it’s the email.

---

<div class="post-metadata">

### Author: ![ehdubya](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/ehdubya/32/24087_2.png) [@ehdubya](https://community.glideapps.com/u/ehdubya)
#### Post date: [December 11, 2020, 3:07pm UTC](https://community.glideapps.com/t/row-owners/4927/16 "2020-12-11T15:07:33Z")

</div>

Thanks ThinhDinh, email makes the most sense. So would that be the Glide anon email or the “captured” email at sign-up process?

---

<div class="post-metadata">

### Author: ![Drearystate](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/drearystate/32/49605_2.png) [@Drearystate](https://community.glideapps.com/u/Drearystate)
#### Post date: [December 11, 2020, 3:07pm UTC](https://community.glideapps.com/t/row-owners/4927/17 "2020-12-11T15:07:39Z")

</div>

On rare occasions when I’m being lazy I use a username or person’s real name but it’s best practice to use their email since that doesn’t normally change across the app and it’s sheets.

---

<div class="post-metadata">

### Author: ![ehdubya](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/ehdubya/32/24087_2.png) [@ehdubya](https://community.glideapps.com/u/ehdubya)
#### Post date: [December 11, 2020, 3:08pm UTC](https://community.glideapps.com/t/row-owners/4927/18 "2020-12-11T15:08:48Z")

</div>

Thanks Drearystate.

---

<div class="post-metadata">

### Author: ![ThinhDinh](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/thinhdinh/32/49_2.png) [@ThinhDinh](https://community.glideapps.com/u/ThinhDinh)
#### Post date: [December 11, 2020, 3:08pm UTC](https://community.glideapps.com/t/row-owners/4927/19 "2020-12-11T15:08:51Z")

</div>

Whatever works for your case, I believe since Glide enables the anonymous email option, they’re basically the same.

---

<div class="post-metadata">

### Author: ![Drearystate](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/drearystate/32/49605_2.png) [@Drearystate](https://community.glideapps.com/u/Drearystate)
#### Post date: [December 11, 2020, 3:09pm UTC](https://community.glideapps.com/t/row-owners/4927/20 "2020-12-11T15:09:55Z")

</div>

If your using username and password as your means of signing in that may change how you determine what you sre using because that doesn’t necessarily mean you have the same email time and time again.

---

<div class="post-metadata">

### Author: ![ehdubya](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/ehdubya/32/24087_2.png) [@ehdubya](https://community.glideapps.com/u/ehdubya)
#### Post date: [December 11, 2020, 3:10pm UTC](https://community.glideapps.com/t/row-owners/4927/21 "2020-12-11T15:10:29Z")

</div>

Gotcha. It’s essentially a mask of the persons email they use to sign-in.

[Next page](https://community.glideapps.com/t/row-owners/4927.md?page=2)
