Getting Started

Tutorial: Building with CleaveDB

Enrichment with masking

When building secure, multi-tenant applications, computed fields often calculate sensitive indicators—such as credit scores, executive compensation tiers, or internal risk ratings. CleaveDB seamlessly unifies ENRICH with MASK to enable Virtual Redaction.

Configuring virtual redaction

First, declare the computed field. Second, apply a role-conditioned mask rule:

CleaveQLExample · Virtual field with dynamic masking
-- 1. Compute age eligibility
ENRICH users WITH is_adult AS age >= 18

-- 2. Redact the computed field for guests
MASK "is_adult" ON users IF my role = "guest"

-- 3. Query records
FIND users WHERE is_adult = true

The query engine filters on the true boolean value (is_adult = true), but when formatting the output for a connection with my role = "guest", the field value is replaced with "[MASKED]".

Protecting financial calculations

Consider an e-commerce platform computing profit margins that should only be visible to financial analysts:

CleaveQLExample · Financial margin masking
-- Compute profit margin on products
ENRICH products WITH margin AS price - wholesale_cost

-- Mask margin from public shoppers and guest viewers
MASK "margin" ON products IF my role = "viewer"

When an unprivileged user queries products:

CleaveQLExample · Output for viewer role
{
  "name": "Mechanical Keyboard",
  "price": 120,
  "margin": "[MASKED]"
}

Administrators and managers querying the same database see the raw calculated number (e.g. 45).

Revoking masks on computed fields

Just like stored fields, security masks on virtual attributes can be revoked at any time using DROP SECURITY:

CleaveQLExample · Revoke mask policy
DROP SECURITY "is_adult" ON users

The mask is cleared and subsequent queries return the unmodified computed value.