# Bug 3178: cell level read permissions

- Status: open
- Project: Zero
- Creator: @tantaman
- Labels: schema
- Created: 2024-12-02T18:11:19Z
- Modified: 2026-10-02T08:42:10Z
- Reactions: ⬆️ ×32 (AceroM, Antonio-Bennett, KidkArolis, MarkLyck, Mat4m0, MatejFrnka, MrPorky, RaeesBhatti, aboodman, alamothe, anaydotdev, arshad-yaseen, austinm911, carlosbensant, celeron450, elledienne, erikmunson, ictnmd, izakfilmalter, jackfraser70, mukama, natew, neoantox, quick007, rohitpaulk, samohovets, snehalbaghel, sonercirit, svetch, tjenkinson, tmm, vaughanlove) · 😿 ×3 (arshad-yaseen, rohitpaulk, sonercirit) · 🙏 ×17 (Antonio-Bennett, Mat4m0, MatejFrnka, RaeesBhatti, aboodman, alamothe, arshad-yaseen, carlosbensant, ictnmd, izakfilmalter, mugoosse, quick007, rohitpaulk, saibotma, samohovets, sonercirit, vaughanlove)
- URL: https://bugs.rocicorp.dev/p/zero/issue/3178

## Description

We need some way to implement "cell-level permissions". e.g., imagine a `user.phone_number` column. The user should be able to read it, and perhaps their administrator. But other users should not.

This can be worked around currently by factoring the private columns into a separate table, e.g., `user_private`. Then, ZQL can be used to control access to that entire row. But it would be nice to have a solution that didn't require refactoring the schema.

## Comments (6)

### @izakfilmalter — 2025-05-12T11:28:50Z

Would love this for my user object. I am using better-auth so I am kinda stuck with their schema form a table pov. I don't want users to be able to mutate them selves into being an admin.

Reactions: ⬆️ ×5 (MarkLyck, RaeesBhatti, amerkestijn, quynhnt223, saibotma) · 👆️ ×2 (MarkLyck, quynhnt223) · 💯 ×2 (MarkLyck, quynhnt223)

### @aboodman — 2026-02-10T17:56:51Z

Note: Izaks comment is now out of date. With custom mutators (default as of Zero 0.25) you can control exactly what is *editable*. Just not what is readable.

Reactions: 👍️ ×1 (rohitpaulk)

### @rohitpaulk — 2026-06-13T14:52:38Z

With queries, can't you control what is readable too since they're validated on the server?

### @MatejFrnka — 2026-07-24T21:18:26Z

I would love to be able to control which columns are synced in queries. 

This is a must have feature for my usecase where I must not sync columns like phone numbers for some users based on their roles.

I would be able to solve this by defining queries with different subsets of columns returned.

### @arshad-yaseen — 2026-09-07T12:25:43Z

Cool

### @tjenkinson — 2026-10-02T08:42:10Z

This would be a super useful feature for us. We've had to workaround it in a few places by creating tables with a single data column and join back to the main table (with that table synced from the main one with pg triggers), which is quite a lot of overhead. Would be great to clean this up.
