Role-Based Security
A complete security setup: module roles, entity access with XPath row-level constraints, document access, user roles, and demo users.
Module Roles
Module roles define what actions are available within a module:
mdl 1;
CREATE MODULE ROLE Sales.Viewer DESCRIPTION 'Read-only access to sales data';
CREATE MODULE ROLE Sales.User DESCRIPTION 'Can create and edit orders';
CREATE MODULE ROLE Sales.Admin DESCRIPTION 'Full access including delete';
Entity Access
GRANT controls which CRUD operations a role can perform. XPath constraints in WHERE filter which rows are visible:
mdl 1;
-- Admin: full access to all customers
GRANT CREATE, DELETE, READ *, WRITE * ON ENTITY Sales.Customer TO Sales.Admin;
-- User: can create and edit, but only active customers
GRANT CREATE, READ *, WRITE * ON ENTITY Sales.Customer TO Sales.User
WHERE [IsActive = true];
-- Viewer: read-only, active customers only
GRANT READ * ON ENTITY Sales.Customer TO Sales.Viewer
WHERE [IsActive = true];
-- Orders: users can only see their own (via owner token)
GRANT CREATE, READ *, WRITE * ON ENTITY Sales.Order TO Sales.User
WHERE [System.owner = '[%CurrentUser%]'];
-- Admin sees all orders
GRANT CREATE, DELETE, READ *, WRITE * ON ENTITY Sales.Order TO Sales.Admin;
Microflow and Page Access
mdl 1;
-- Microflow access
GRANT EXECUTE ON MICROFLOW Sales.ACT_Order_Save TO Sales.User;
GRANT EXECUTE ON MICROFLOW Sales.ACT_Order_Delete TO Sales.Admin;
-- Page access
GRANT VIEW ON PAGE Sales.Customer_Overview TO Sales.Viewer;
GRANT VIEW ON PAGE Sales.Customer_Overview TO Sales.User;
GRANT VIEW ON PAGE Sales.Order_Edit TO Sales.User;
GRANT VIEW ON PAGE Sales.Admin_Dashboard TO Sales.Admin;
User Roles
User roles combine module roles from different modules into a single assignable role:
mdl 1;
CREATE OR MODIFY USER ROLE SalesViewer ( ModuleRoles: (System.User, Sales.Viewer) );
CREATE OR MODIFY USER ROLE SalesRep ( ModuleRoles: (System.User, Sales.User) );
CREATE OR MODIFY USER ROLE SalesManager ( ModuleRoles: (System.User, Sales.Admin), ManageAllRoles: true );
Demo Users
Demo users are created for testing and development:
mdl 1;
CREATE OR MODIFY DEMO USER 'viewer' ( Password: 'Password1!', UserRoles: (SalesViewer) );
CREATE OR MODIFY DEMO USER 'sales_rep' ( Password: 'Password1!', UserRoles: (SalesRep) );
CREATE OR MODIFY DEMO USER 'manager' ( Password: 'Password1!', UserRoles: (SalesManager) );
-- Enable demo users in project security
ALTER APP SECURITY ( EnableDemoUsers: TRUE );
Additive Grants
GRANT merges with existing access — it never removes permissions:
-- Viewer already has READ (Name, Email)
GRANT READ (Phone) ON ENTITY Sales.Customer TO Sales.Viewer;
-- Result: READ (Name, Email, Phone)
Revoking Access
mdl 1;
-- Remove all access for a role
REVOKE ALL ON ENTITY Sales.Customer FROM Sales.Viewer;
-- Partial revoke: remove read on a specific attribute
REVOKE READ (Phone) ON ENTITY Sales.Customer FROM Sales.User;
-- Partial revoke: downgrade write to read-only
REVOKE WRITE (Email) ON ENTITY Sales.Customer FROM Sales.User;
-- Remove microflow access
REVOKE EXECUTE ON MICROFLOW Sales.ACT_Order_Delete FROM Sales.User;