Data Security Roles restrict which records a user can see within an object. Before rules take effect, data security must be enabled on the object itself — navigate to the object's configuration and ensure Apply Data Security is turned on.
Data Security Roles are managed in Configuration \> Security \> Data Security Roles.
Creating a Data Security Role
Open the Configuration application.
Navigate to Security \> Data Security Roles.
In the Data Security Role section, select New.
Enter the number of roles to create and select Add.
Enter a name for each role.
Enter an audit comment.
Save the changes.
A Data Security Role represents a type of access level, not an individual user. Multiple users can be assigned to the same Data Security Role.
Assigning Users to a Data Security Role
Open Security \> Data Security Roles.
In the User Security Role section, select Edit.
Enter the number of records to create and select Add.
Enter the user's email address.
Select the Data Security Role to assign.
Enter an audit comment.
Save the changes.
Defining Data Security Rules
Rules define which records a Data Security Role can access. The rule's Term value is matched against the unique key of the object's records — only matching records are visible to the user.
Open Security \> Data Security Roles.
Select the Data Security Role to configure.
In the Role Security Filter section, select Edit.
Enter the number of rules to create and select Add.
Select the object containing the records to restrict.
Enter a term that identifies the records the role should be able to access.
Repeat for each rule required.
Enter an audit comment.
Save the changes.
For guidance on using wildcards and special terms in rule expressions, see Data Security Filter Reference.
Key Behaviours
Rules apply to the object where data security is enabled and automatically propagate to any objects that directly reference it. Objects that reference the secured object indirectly do not inherit restrictions automatically.
Multiple Data Security Roles can apply to the same object. A user assigned to more than one role sees the union of records permitted across all their assigned roles.
When processes run in the background, they use the SUPER_USER Data Security Role and are not subject to any data security restrictions.
