How Data Access Control Enforcement Works in the Live App and API

See exactly how Knack enforces Data Access Control rules in the Live App and through the API, including the messages and error codes users and developers will see.

What You'll Learn

This article covers what happens when Data Access Control (DAC) enforcement is turned on in your Knack app. You'll learn how restricted actions behave in the Live App, and what response codes the Knack API returns for the same restrictions.

📘

Haven't enforced your rules yet?

This article describes behavior after enforcement is on. See Setting Up and Enforcing Data Access Control for the setup steps.

How Enforcement Affects the Live App

Once enforcement is on, Knack checks your permissions on every request, including form submissions, record deletions, and record creation attempts. If a user's role doesn't allow an action, Knack rejects the request at the server level with an HTTP 403 response and shows a message explaining why. This happens consistently across pages, elements, inline edits, modals, and API calls.

ActionWhat HappensMessage Shown to User
Edit or SaveThe form renders as read-only. Fields and connection dropdowns are disabled, and the Save button doesn't appear."Your access to this record is view-only."
DeleteThe request is blocked with an HTTP 403 response."Your access to this record doesn't include deletion."
CreateThe request is blocked with an HTTP 403 response."Your access doesn't include adding records here."
📘

No extra configuration needed

Knack surfaces these messages automatically once Data Access rules are active. You don't need to add display rules or page logic to communicate restrictions to users.

How Enforcement Affects the Knack API

Data Access rules apply to API requests the same way they apply in the Live App. If an authenticated user's role doesn't permit the attempted operation, the API returns an HTTP 403 Forbidden response for PUT, DELETE, and POST requests.

⚠️

Handle 403 responses in your integration

If you're building against the Knack API, don't assume every request will succeed. Handle 403 responses in your code and surface clear messaging to your end users.

Common Mistakes

  • Not handling 403 responses in custom integrations. If your app calls the Knack API directly, build in handling for 403 responses instead of assuming every request will succeed.
  • Building custom error messaging for restricted actions. Knack already surfaces the right message in the Live App. You don't need display rules or page logic to duplicate this.
  • Testing only in the Builder. Enforcement behavior shows up in the Live App and the API, not the Builder preview. Test as each role in the actual Live App to confirm restrictions work as expected.

Next Steps


Did this page help you?