Setting Up and Enforcing Data Access Control

Step-by-step instructions for configuring the Data Access grid in Knack, setting defaults for new tables, and turning on enforcement.

What You'll Learn

This article walks through setting up Data Access Control (DAC) in your Knack app, from initial setup to turning on enforcement. You'll also learn how to set defaults for new tables and how to turn enforcement off if you need to.

📘

New to Data Access Control?

If you haven't already, read Data Access Control first. It covers the permission model and access levels this setup workflow configures.

Step 1: Start Setup

Go to Users > All Users > Data Access and click Start Setup. This creates the Data Access grid and sets default permissions for every existing role and table in your app.

📘

Your Live App is safe during setup

Your Live App isn't affected by these settings until you review your permissions and turn on enforcement.

Step 2: Configure Permissions

The Data Access grid lists your tables as rows and your user roles as column groups, each split into Owned By User and All Other Records. Click any dropdown in the grid to change a permission.

Filtering the Grid by Role

Use the role filter dropdown in the upper right to narrow the grid to specific roles. Select Select all to show or hide every role, or check individual roles to focus on just those. Selected roles show as tags above the grid.

Configuring a Single Role

To configure one role at a time, select it from the dropdown filter or the left-hand role list. You'll see the same grid, filtered to that role.

📘

The Public role defaults to No Access

The Public (Not Logged-In) role defaults to No Access for All Other Records on every table. This keeps unauthenticated traffic locked out by default.

Setting Default Permissions for New Tables

You can set default permissions so new tables automatically inherit the right access rules for each role, instead of configuring each new table manually.

  1. Go to Users > All Users, click the ellipsis (...) in the upper right, and select User Role Settings.
  2. Select a role from the left-hand list.
  3. Scroll to Default Permission for Records Owned by User and Default Permission for All Other Records.
  4. Set your preferred defaults and click Save.

Every new table you create after this inherits these defaults for that role.

📘

Owned By defaults differ by record type

User Role records are automatically owned by the user they represent. Records in a data table are owned by the user who created them.

Step 3: Enforce Your Rules

Configuring permissions doesn't affect your Live App until you turn on enforcement. This gives you room to set up and review your entire security model before anything goes live.

While enforcement is off, role-specific Data Access pages show a yellow Action Required banner telling you permissions won't take effect until you enforce them. You can click the banner's Enforce Permissions in the All Users Table button to jump straight to the toggle.

When you're ready, go to Users > All Users > Data Access, and in the Step 2: Apply box, toggle Enforce data access rules for App to ON. Your rules now apply to every Live App user, in both Classic and Next Gen.

📘

Want to know what happens after enforcement?

See How Data Access Control Enforcement Works in the Live App and API for the exact behavior users and API callers will see.

Turning Off Enforcement

You can turn off enforcement at any time from Users > All Users > Data Access. When you toggle enforcement off, a confirmation modal warns you that all users will be able to access records as if no rules exist. Your configured grid isn't deleted. It's paused, and you can re-enforce it whenever you're ready.

Common Mistakes

  • Forgetting to turn on enforcement. Configuring the grid doesn't protect your data by itself. Rules only take effect after you toggle enforcement on in the All Users table.
  • Not setting defaults before scaling up. If you skip setting default permissions for new tables, every table you add later needs manual configuration for every role.
  • Confusing "turn off enforcement" with "delete configuration." Turning off enforcement pauses your rules. It doesn't erase the grid you built.

Next Steps


Did this page help you?