# 🆕 Security Center

**URL:** <https://community.glideapps.com/t/security-center/16542>\
**Category:** General\
**Created:** [September 30, 2020, 12:19am UTC](https://community.glideapps.com/t/security-center/16542 "2020-09-30T00:19:06Z")\
**Posts on this page:** 20\
**Page:** 2

<div class="post-metadata">

**Author:** ![Lucas\_Pires](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/lucas_pires/32/64863_2.png) [@Lucas\_Pires](https://community.glideapps.com/u/Lucas_Pires)\
**Post date:** [September 30, 2020, 1:30am UTC](https://community.glideapps.com/t/security-center/16542/21 "2020-09-30T01:30:31Z")

</div>

Thanks David! This will clarify some points by now

---

<div class="post-metadata">

**Author:** ![Wiz.Wazeer](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/wiz.wazeer/32/72423_2.png) [@Wiz.Wazeer](https://community.glideapps.com/u/Wiz.Wazeer)\
**Post date:** [September 30, 2020, 2:44am UTC](https://community.glideapps.com/t/security-center/16542/22 "2020-09-30T02:44:20Z")

</div>

Thank you! Great +1: 👍 👍

---

<div class="post-metadata">

**Author:** ![Robert\_Petitto](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/robert_petitto/32/25193_2.png) [@Robert\_Petitto](https://community.glideapps.com/u/Robert_Petitto)\
**Post date:** [September 30, 2020, 3:36am UTC](https://community.glideapps.com/t/security-center/16542/23 "2020-09-30T03:36:18Z")

</div>

Thanks @David. This gives me a lot to consider. I see that you have a section on [Mirroring columns](https://docs.glideapps.com/all/guides/security-center/use-row-owners-to-protect-private-data#mirroring-columns-across-sheets-for-different-views).

Effectively, this could double the amount of rows in our app in order to make them more secure. Any thought, then to increase the row limit to ensure all apps created with Glide have this security measure?

---

<div class="post-metadata">

**Author:** ![\_eric](https://avatars.discourse-cdn.com/v4/letter/_/5f9b8f/32.png) [@\_eric](https://community.glideapps.com/u/_eric)\
**Post date:** [September 30, 2020, 3:45am UTC](https://community.glideapps.com/t/security-center/16542/24 "2020-09-30T03:45:07Z")

</div>

@Robert_Petitto you read my mind. Sounds like a lot more row usage to secure some parts of the app.

I’m also curious how arrays will be handled in glide sheets

---

<div class="post-metadata">

**Author:** ![david](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/david/32/62831_2.png) [@david](https://community.glideapps.com/u/david)\
**Post date:** [September 30, 2020, 4:47am UTC](https://community.glideapps.com/t/security-center/16542/25 "2020-09-30T04:47:37Z")

</div>

We’re working on features that obviate the sheet mirroring techniques.

---

<div class="post-metadata">

**Author:** ![Petr\_Shemyagin](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/petr_shemyagin/32/59902_2.png) [@Petr\_Shemyagin](https://community.glideapps.com/u/Petr_Shemyagin)\
**Post date:** [September 30, 2020, 4:50am UTC](https://community.glideapps.com/t/security-center/16542/26 "2020-09-30T04:50:37Z")

</div>

Hey David!

Sorry, not agree with this statement.

I constantly use “Public” access type to allow users to see what’s inside the app and only after that sign-in with the sign-in button. That’s the basic UX principle, because it’s not really good to ask people log-in into the app when they do not see the value of the app.

For example, I have a restaurant app. It is public and you can sign-in, see which dishes they have, check other information. But when a client wants to order a dish he see the sign-in button on the dish page and only after signing-in he can use a lot more functions.

And I need some admins and employees that will also see and check the orders and manage the app without using the go.glideapps constructor (changing images, dishes and etc).

And that’s only one example, I have like 30% of my apps that are public but need to have admins and that’s not the one admin.

---

<div class="post-metadata">

**Author:** ![david](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/david/32/62831_2.png) [@david](https://community.glideapps.com/u/david)\
**Post date:** [September 30, 2020, 4:52am UTC](https://community.glideapps.com/t/security-center/16542/27 "2020-09-30T04:52:34Z")

</div>

I didn’t say the feature would not be useful in public apps. I said that allowing it in public apps would be incompatible with our business.

---

<div class="post-metadata">

**Author:** ![Roldy](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/roldy/32/36068_2.png) [@Roldy](https://community.glideapps.com/u/Roldy)\
**Post date:** [September 30, 2020, 9:41am UTC](https://community.glideapps.com/t/security-center/16542/28 "2020-09-30T09:41:51Z")

</div>

Thanks @kyleheney I will try this technique

---

<div class="post-metadata">

**Author:** ![kyleheney](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/kyleheney/32/41173_2.png) [@kyleheney](https://community.glideapps.com/u/kyleheney)\
**Post date:** [September 30, 2020, 10:58am UTC](https://community.glideapps.com/t/security-center/16542/29 "2020-09-30T10:58:51Z")

</div>

Idea: Some sort of mirroring function to build a full Glide Table would be sweet. Then it wouldn’t only mirror the sheet contents, but any lookups, templates, etc that were created in the “secure” version of the sheet. A mirrored Glide Table could be set up in such a way that clearly makes it a mirror of another sheet and would not count towards row limits (since it’s just mirrored content).

---

<div class="post-metadata">

**Author:** ![spencersRus](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/spencersrus/32/69_2.png) [@spencersRus](https://community.glideapps.com/u/spencersRus)\
**Post date:** [September 30, 2020, 11:53am UTC](https://community.glideapps.com/t/security-center/16542/30 "2020-09-30T11:53:03Z")

</div>

> [@david](#):
>
> obviate

Now googling “obviate” - trying to weave it seamlessly in a sentence today.

---

<div class="post-metadata">

**Author:** ![Deena](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/deena/32/9877_2.png) [@Deena](https://community.glideapps.com/u/Deena)\
**Post date:** [September 30, 2020, 12:32pm UTC](https://community.glideapps.com/t/security-center/16542/31 "2020-09-30T12:32:11Z")

</div>

Thank you David, Mark, entire Glide team! Having a central security resource is extremely helpful to non-dev users like me and will help everyone new to Glide set up correctly from the beginning!

---

<div class="post-metadata">

**Author:** ![Robert\_Petitto](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/robert_petitto/32/25193_2.png) [@Robert\_Petitto](https://community.glideapps.com/u/Robert_Petitto)\
**Post date:** [September 30, 2020, 12:32pm UTC](https://community.glideapps.com/t/security-center/16542/32 "2020-09-30T12:32:14Z")

</div>

> [@spencersRus](#):
>
> > [@david](#):
> >
> > obviate
> 
> Now googling “obviate” - trying to weave it seamlessly in a sentence today.

Not going to lie—totally thought David wrote “obliviate”—which is a spell from Harry Potter  
 ![](https://us1.discourse-cdn.com/flex002/uploads/glideapps/original/2X/c/c2f475e57a63d81f10bb859646f84b72fdf4f976.gif)

---

<div class="post-metadata">

**Author:** ![Messias\_Carvalho](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/messias_carvalho/32/4586_2.png) [@Messias\_Carvalho](https://community.glideapps.com/u/Messias_Carvalho)\
**Post date:** [September 30, 2020, 1:30pm UTC](https://community.glideapps.com/t/security-center/16542/33 "2020-09-30T13:30:02Z")

</div>

Thanks for concern 🙏 🔒

---

<div class="post-metadata">

**Author:** ![\_eric](https://avatars.discourse-cdn.com/v4/letter/_/5f9b8f/32.png) [@\_eric](https://community.glideapps.com/u/_eric)\
**Post date:** [September 30, 2020, 3:03pm UTC](https://community.glideapps.com/t/security-center/16542/34 "2020-09-30T15:03:28Z")

</div>

@david , will stripe payments be transitioned over to Glide Sheets? Currently the payments only populate into Google Sheet. But the sheet itself is missing from component connectivity.

---

<div class="post-metadata">

**Author:** ![Wiz.Wazeer](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/wiz.wazeer/32/72423_2.png) [@Wiz.Wazeer](https://community.glideapps.com/u/Wiz.Wazeer)\
**Post date:** [September 30, 2020, 7:04pm UTC](https://community.glideapps.com/t/security-center/16542/35 "2020-09-30T19:04:05Z")

</div>

Mirroring is something I do all the time as 99% of my apps are multiple sign up temps.There is no other way, and I prefer this method, to be quite honest (but see below). I can secure rows/columns. However, I have found another way of achieving the same end, but it requires duplication of all relevant components, instead of the sheet, and then setting the same component to as either when access level admin. staff, driver, etc, This way I can make the same component display different bits information to different users. It is arduous, and sometimes slips are possible. I really milked this approach when developing the taxi app and now use on all my templates as the risks associated with deleting (most of the time by me lol) info on duplicated sheets living on the back of a live source sheet can be costly. The other advantage I have when using the second approach is I am able to avoid incurring additional rows eating into my limit.

I would if at all possible like to see mirroring of entire tabs.

---

<div class="post-metadata">

**Author:** ![rayo](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/rayo/32/91372_2.png) [@rayo](https://community.glideapps.com/u/rayo)\
**Post date:** [October 1, 2020, 11:20pm UTC](https://community.glideapps.com/t/security-center/16542/36 "2020-10-01T23:20:59Z")

</div>

correct me if I am wrong,  
if my app has premium content for subscribed users only (ex. premium courses) hiding this content with visibility conditions is not safe, as the app still downloads that data if a free user is signed in.

so for the rows for premium content lets say in (ex. courses sheet). do i need to have row owners consisting of a list of emails of the premium users, and every time a new user subscribed this list must be updated?

---

<div class="post-metadata">

**Author:** ![Lisa](https://avatars.discourse-cdn.com/v4/letter/l/f08c70/32.png) [@Lisa](https://community.glideapps.com/u/Lisa)\
**Post date:** [October 2, 2020, 10:43pm UTC](https://community.glideapps.com/t/security-center/16542/37 "2020-10-02T22:43:42Z")

</div>

@david, when assigning multiple row owners, does this only work for array columns? I’d love to be able to apply this to relation columns…

 ![image](https://us1.discourse-cdn.com/flex002/uploads/glideapps/original/2X/2/28fe54ab98895428990c243db3cb239e70663f98.png)

---

<div class="post-metadata">

**Author:** ![Jeff\_Hager](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/jeff_hager/32/43_2.png) [@Jeff\_Hager](https://community.glideapps.com/u/Jeff_Hager)\
**Post date:** [October 3, 2020, 12:05am UTC](https://community.glideapps.com/t/security-center/16542/38 "2020-10-03T00:05:36Z")

</div>

@Lisa According to this, I think it’s only columns that originate from the sheet. I’m assuming that includes Lookup from a Relation.

> [@new Security Center](https://community.glideapps.com/t/security-center/16542/5):
>
> You cannot assign computed columns as Row Owners yet—only basic columns of emails, or arrays of emails.

---

<div class="post-metadata">

**Author:** ![Jeff\_Hager](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/jeff_hager/32/43_2.png) [@Jeff\_Hager](https://community.glideapps.com/u/Jeff_Hager)\
**Post date:** [October 3, 2020, 12:13am UTC](https://community.glideapps.com/t/security-center/16542/39 "2020-10-03T00:13:32Z")

</div>

@rayo From what I understand, yes, the only way to assure row owners and to restrict premium content data from being downloaded to only premium user devices, in your case would be to add an email to an array column in the google sheet. In my opinion, a user would have to be pretty tech savvy to even discover that the additional data was downloaded to their device. If you data does not contain personal information, then I feel it would not be as critical. Personally I feel that Row Owners would be most applicable to situations where PII is involved in an app that’s share among multiple users.

---

<div class="post-metadata">

**Author:** ![Gideon\_Lahav\_Busines](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/gideon_lahav_busines/32/41121_2.png) [@Gideon\_Lahav\_Busines](https://community.glideapps.com/u/Gideon_Lahav_Busines)\
**Post date:** [October 4, 2020, 1:47pm UTC](https://community.glideapps.com/t/security-center/16542/40 "2020-10-04T13:47:48Z")

</div>

Great job!! thank you

Gideon

[Previous page](https://community.glideapps.com/t/security-center/16542.md?page=1)

[Next page](https://community.glideapps.com/t/security-center/16542.md?page=3)
