Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

GRANT / REVOKE

The GRANT and REVOKE statements control all permissions in a Mendix project. They work on three targets: entities (CRUD access), microflows (execute access), and pages (view access).

Entity Access

GRANT

GRANT <rights> ON ENTITY <Module>.<Entity> TO <Module>.<Role> [, ...] [WHERE [<xpath>]];

Where <rights> is a comma-separated list of:

RightDescription
CREATEAllow creating new objects
DELETEAllow deleting objects
READ *Read all members
READ (<attr>, ...)Read specific members only
WRITE *Write all members
WRITE (<attr>, ...)Write specific members only

GRANT is additive: if the role already has an access rule on the entity, new rights are merged in. Existing permissions are never removed by a GRANT — only upgraded.

Examples:

mdl 1;
-- Full access
GRANT CREATE, DELETE, READ *, WRITE * ON ENTITY Shop.Customer TO Shop.Admin;

-- Read-only
GRANT READ * ON ENTITY Shop.Customer TO Shop.Viewer;

-- Selective members
GRANT READ (Name, Email), WRITE (Email) ON ENTITY Shop.Customer TO Shop.User;

-- With XPath constraint (doubled single quotes for string literals)
GRANT READ *, WRITE * ON ENTITY Shop.Order TO Shop.User
  WHERE [Status = 'Open'];

-- Additive: adds Notes to existing read access without removing Name, Email
GRANT READ (Notes) ON ENTITY Shop.Customer TO Shop.User;

REVOKE

Remove an entity access rule entirely, or revoke specific rights:

-- Full revoke (removes entire rule)
REVOKE <Module>.<Role> ON <Module>.<Entity>;

-- Partial revoke (downgrades specific rights)
REVOKE <Module>.<Role> ON <Module>.<Entity> (<rights>);

For partial revoke, REVOKE READ (x) sets member x access to None. REVOKE WRITE (x) downgrades member x from ReadWrite to ReadOnly. REVOKE CREATE / REVOKE DELETE removes the structural permission.

Examples:

mdl 1;
-- Remove all access
REVOKE ALL ON ENTITY Shop.Customer FROM Shop.Viewer;

-- Remove read access on a specific member
REVOKE READ (Notes) ON ENTITY Shop.Customer FROM Shop.User;

-- Downgrade write to read-only
REVOKE WRITE (Email) ON ENTITY Shop.Customer FROM Shop.User;

-- Remove delete permission only
REVOKE DELETE ON ENTITY Shop.Customer FROM Shop.User;

Microflow Access

GRANT EXECUTE ON MICROFLOW

GRANT EXECUTE ON MICROFLOW <Module>.<Name> TO <Module>.<Role> [, ...];

Example:

GRANT EXECUTE ON MICROFLOW Shop.ACT_ProcessOrder TO Shop.User, Shop.Admin;

REVOKE EXECUTE ON MICROFLOW

REVOKE EXECUTE ON MICROFLOW <Module>.<Name> FROM <Module>.<Role> [, ...];

Example:

REVOKE EXECUTE ON MICROFLOW Shop.ACT_ProcessOrder FROM Shop.User;

Page Access

GRANT VIEW ON PAGE

GRANT VIEW ON PAGE <Module>.<Name> TO <Module>.<Role> [, ...];

Example:

GRANT VIEW ON PAGE Shop.Order_Overview TO Shop.User, Shop.Admin;

REVOKE VIEW ON PAGE

REVOKE VIEW ON PAGE <Module>.<Name> FROM <Module>.<Role> [, ...];

Example:

REVOKE VIEW ON PAGE Shop.Admin_Dashboard FROM Shop.User;

Nanoflow Access

GRANT EXECUTE ON NANOFLOW <Module>.<Name> TO <Module>.<Role> [, ...];
REVOKE EXECUTE ON NANOFLOW <Module>.<Name> FROM <Module>.<Role> [, ...];

Workflow Access

Not supported. Mendix workflows do not have document-level AllowedModuleRoles (unlike microflows and pages). Workflow access is controlled through the microflow that triggers the workflow and UserTask targeting.

OData Service Access

GRANT ACCESS ON PUBLISHED ODATA SERVICE <Module>.<Name> TO <Module>.<Role> [, ...];
REVOKE ACCESS ON PUBLISHED ODATA SERVICE <Module>.<Name> FROM <Module>.<Role> [, ...];

Complete Example

A typical security setup script:

mdl 1;
-- Module roles
CREATE MODULE ROLE Shop.Admin DESCRIPTION 'Full access';
CREATE MODULE ROLE Shop.User DESCRIPTION 'Standard access';
CREATE MODULE ROLE Shop.Viewer DESCRIPTION 'Read-only access';

-- User roles
CREATE USER ROLE Administrator ( ModuleRoles: (Shop.Admin, System.Administrator), ManageAllRoles: true );
CREATE USER ROLE Employee ( ModuleRoles: (Shop.User) );
CREATE USER ROLE Guest ( ModuleRoles: (Shop.Viewer) );

-- Entity access
GRANT CREATE, DELETE, READ *, WRITE * ON ENTITY Shop.Customer TO Shop.Admin;
GRANT READ *, WRITE (Email, Phone) ON ENTITY Shop.Customer TO Shop.User;
GRANT READ * ON ENTITY Shop.Customer TO Shop.Viewer;

GRANT CREATE, DELETE, READ *, WRITE * ON ENTITY Shop.Order TO Shop.Admin;
GRANT CREATE, READ *, WRITE * ON ENTITY Shop.Order TO Shop.User
  WHERE [Status = 'Open'];
GRANT READ * ON ENTITY Shop.Order TO Shop.Viewer;

-- Microflow access
GRANT EXECUTE ON MICROFLOW Shop.ACT_ProcessOrder TO Shop.Admin;
GRANT EXECUTE ON MICROFLOW Shop.ACT_CreateOrder TO Shop.User, Shop.Admin;
GRANT EXECUTE ON MICROFLOW Shop.ACT_ViewOrders TO Shop.User, Shop.Admin, Shop.Viewer;

-- Page access
GRANT VIEW ON PAGE Shop.Order_Overview TO Shop.User, Shop.Admin, Shop.Viewer;
GRANT VIEW ON PAGE Shop.Order_Edit TO Shop.User, Shop.Admin;
GRANT VIEW ON PAGE Shop.Admin_Dashboard TO Shop.Admin;

-- Demo users
CREATE DEMO USER 'demo_admin' ( Password: 'Admin123!', UserRoles: (Administrator) );
CREATE DEMO USER 'demo_user' ( Password: 'User123!', UserRoles: (Employee) );

-- Enable demo users
ALTER APP SECURITY ( EnableDemoUsers: TRUE );
ALTER APP SECURITY ( SecurityLevel: PROTOTYPE );

See Also