Tutorial: Building with CleaveDB
Enrichment with masking
When building secure, multi-tenant applications, computed fields often calculate sensitive indicators—such as credit scores, executive compensation tiers, or internal risk ratings. CleaveDB seamlessly unifies ENRICH with MASK to enable Virtual Redaction.
Configuring virtual redaction
First, declare the computed field. Second, apply a role-conditioned mask rule:
-- 1. Compute age eligibility
ENRICH users WITH is_adult AS age >= 18
-- 2. Redact the computed field for guests
MASK "is_adult" ON users IF my role = "guest"
-- 3. Query records
FIND users WHERE is_adult = trueThe query engine filters on the true boolean value (is_adult = true), but when formatting the output for a connection with my role = "guest", the field value is replaced with "[MASKED]".
Protecting financial calculations
Consider an e-commerce platform computing profit margins that should only be visible to financial analysts:
-- Compute profit margin on products
ENRICH products WITH margin AS price - wholesale_cost
-- Mask margin from public shoppers and guest viewers
MASK "margin" ON products IF my role = "viewer"When an unprivileged user queries products:
{
"name": "Mechanical Keyboard",
"price": 120,
"margin": "[MASKED]"
}Administrators and managers querying the same database see the raw calculated number (e.g. 45).
Revoking masks on computed fields
Just like stored fields, security masks on virtual attributes can be revoked at any time using DROP SECURITY:
DROP SECURITY "is_adult" ON usersThe mask is cleared and subsequent queries return the unmodified computed value.
