Tutorial: Building with CleaveDB
Security & Access Control — Overview
In traditional database architectures, security rules and access gates are often implemented in fragile external application middleware. CleaveDB moves access control directly into the database engine through native Data-Level Security (DLS)—also referred to as Document Security Level (DSL) Policies.
The DLS security triad
GBAC
Graph-Based Access Control: Determines permissions based on relationship topology—granting read or write rights only if an entity is connected by specific graph bonds (e.g., bonded as "owner").
RBAC
Role-Based Access Control: Compares active session roles and attributes (such as my role = "admin") against document properties.
Dynamic Masking
Field-Level Redaction: Instead of hiding entire documents, conditionally redacts sensitive fields (like salaries or SSNs) based on the caller's identity.
Security command suite
| Command | Purpose | Canonical example |
|---|---|---|
| ENFORCE SECURITY | Declarative read/write policy gate | ENFORCE SECURITY "adm" ON docs TO ALLOW all IF my role = "admin" |
| MASK | Conditionally redact sensitive JSON fields | MASK "salary" ON staff IF my role != "admin" |
| LIMIT | Rate limiting per role per minute | LIMIT 100 QUERIES PER MINUTE FOR "viewer" |
| SET | Inject session context variables | SET role = "viewer", tenant_id = "acme" |
| AUTHENTICATE | Set active caller identity | AUTHENTICATE AS "david" |
| DROP SECURITY | Revoke or delete an existing policy rule | DROP SECURITY "adm" ON docs |
Explore the Security topics
Review each guide to implement end-to-end security in CleaveDB:
- Enforce security policies: configure GBAC and RBAC gates on read and write operations.
- Field masking (MASK): redact confidential attributes dynamically without hiding documents.
- Rate limiting (LIMIT): throttle queries per minute and defend against denial-of-service spikes.
- Session context (SET): pass arbitrary variables into active client sessions for real-time policy evaluation.
- Authenticate (AUTHENTICATE): set caller identity and enforce multi-tenant isolation.
- Remove policies: cleanly drop active security rules and field masks.
