Field Privileges — Field-Level Access Control & Masking
Access, granted to a single field. Decide who can read or write each field, mask sensitive values, and issue temporary privileges that expire automatically.
Overview
Roles decide broad access, but real governance lives at the field. A support agent may need a customer's name and ticket history without ever seeing a full bank account or Aadhaar number. Field Privileges lets you set read and write control on a single field, so people see exactly what their job requires and nothing more.
Every grant is enforced by the platform itself, not left to good intentions. Field permissions, masking rules, record-sharing rules and time-boxed privilege grants work together so that even the Flow-Cognition Agent only ever acts on data it is allowed to see. When a temporary need ends, the extra access is taken back automatically and the whole trail is auditable.
Explore Data & Privileges →- ✓ Read and write control at the level of one field
- ✓ Masking so support helps without seeing full sensitive values
- ✓ Time-boxed privilege grants that expire and are auto-revoked
- ✓ Record-sharing rules beyond the role hierarchy
- ✓ Every grant has an owner, a reason and an audit-log entry
- ✓ Enforced for users, APIs and the AI agent alike
Everything Field Privileges gives you
Field Permissions
Set read and write access on any single field, per role, as the finest grain of control.
Field Masking
Obscure sensitive values with patterns so teams can work without exposing full account or ID numbers.
Time-Boxed Grants
Give a user a specific privilege beyond their role that automatically expires on a set date.
Record Sharing
Share specific records by team, territory or criteria, beyond the standard role hierarchy.
Exempt Roles
Define which roles are exempt from a masking rule so authorised staff still see full values.
Grant Audit Trail
Every permission, grant and share is owned, reviewed and logged for compliance.
How the AI agent respects Field Privileges
The Flow-Cognition Agent reads and writes only the fields its user is allowed to see, and every access is logged.
Sense
Reads only the fields its user is allowed to see.
Decide
Keeps masked values masked in drafts and replies.
Act
Writes only permitted fields, and logs every access.
Field-level permissions · masking · full audit trail. See the AI layer →
Live in four steps
Map Fields
Pick the object and field you want to govern and decide which roles may read or write it.
Set Permissions
Apply read and write rules, add masking patterns, and name any exempt roles.
Grant Temporarily
Issue time-boxed privileges for one-off needs with a reason and an expiry date.
Review & Revoke
Track usage on the permission matrix while expired grants are auto-revoked.
Where teams put it to work
Support without exposure
Agents resolve tickets seeing masked account and card fields, so they help customers without ever viewing full sensitive numbers.
Temporary auditor access
Grant an external auditor read access to specific fields for a fixed window; access is taken back automatically when the review closes.
Cross-team record sharing
A regional team needs a few accounts owned by another territory, shared by criteria without changing the whole role hierarchy.
The payoff
Least-privilege by default
People and agents only reach the exact fields their work requires, cutting exposure at the source.
No standing over-access
Extra privileges are time-boxed and auto-revoked, so temporary needs never become permanent risk.
Audit-ready governance
Every grant, share and permission is owned, reviewed and logged for DPDP and internal audits.
Safer AI actions
The Flow-Cognition Agent inherits the same field rules, so automation never sees what a person cannot.
Questions, answered
Right down to a single field on a single object. You can set read and write separately per role, which is the finest grain of access the platform offers.
Field permissions decide whether a role can see or edit a field at all. Masking lets a role see a field but obscures the value, for example showing only the last few digits of an account number, with exempt roles seeing the full value.
Yes. Each privilege grant carries an expiry date, and when it passes the extra access is automatically taken back. The grant, its reason and its usage remain in the audit log.
It does. The Flow-Cognition Agent and API calls are subject to the same field permissions and masking rules, so no automated path can bypass the controls a person is bound by.
Roles grant access along the hierarchy. Record-sharing rules let you extend access to specific records by team, territory or criteria without reshaping roles, which is useful for collaboration across boundaries.
See Field Privileges in your workflow
Start free, or get a guided walkthrough with our team — on the one platform that runs Data & Analytics and your whole business.

