How Data Access Control Enforcement Works in the Live App and API
See exactly how Knack enforces Data Access Control rules in the Live App and through the API, including the messages and error codes users and developers will see.
What You'll Learn
This article covers what happens when Data Access Control (DAC) enforcement is turned on in your Knack app. You'll learn how restricted actions behave in the Live App, and what response codes the Knack API returns for the same restrictions.
Haven't enforced your rules yet?This article describes behavior after enforcement is on. See Setting Up and Enforcing Data Access Control for the setup steps.
How Enforcement Affects the Live App
Once enforcement is on, Knack checks your permissions on every request, including form submissions, record deletions, and record creation attempts. If a user's role doesn't allow an action, Knack rejects the request at the server level with an HTTP 403 response and shows a message explaining why. This happens consistently across pages, elements, inline edits, modals, and API calls.
| Action | What Happens | Message Shown to User |
|---|---|---|
| Edit or Save | The form renders as read-only. Fields and connection dropdowns are disabled, and the Save button doesn't appear. | "Your access to this record is view-only." |
| Delete | The request is blocked with an HTTP 403 response. | "Your access to this record doesn't include deletion." |
| Create | The request is blocked with an HTTP 403 response. | "Your access doesn't include adding records here." |
No extra configuration neededKnack surfaces these messages automatically once Data Access rules are active. You don't need to add display rules or page logic to communicate restrictions to users.
How Enforcement Affects the Knack API
Data Access rules apply to API requests the same way they apply in the Live App. If an authenticated user's role doesn't permit the attempted operation, the API returns an HTTP 403 Forbidden response for PUT, DELETE, and POST requests.
Handle 403 responses in your integrationIf you're building against the Knack API, don't assume every request will succeed. Handle 403 responses in your code and surface clear messaging to your end users.
Common Mistakes
- Not handling 403 responses in custom integrations. If your app calls the Knack API directly, build in handling for 403 responses instead of assuming every request will succeed.
- Building custom error messaging for restricted actions. Knack already surfaces the right message in the Live App. You don't need display rules or page logic to duplicate this.
- Testing only in the Builder. Enforcement behavior shows up in the Live App and the API, not the Builder preview. Test as each role in the actual Live App to confirm restrictions work as expected.
Next Steps
- Setting Up and Enforcing Data Access Control: Configure the Data Access grid and turn on enforcement if you haven't already.
- Data Access Control: Review the permission model behind these enforcement behaviors.
- Allowing Connected Field Selection Without Table Access: Learn how to let users select from a connection field even when they lack access to the linked table.
Updated about 11 hours ago

