Getting Started
Tutorial: Building with CleaveDB
Remove Policies (DROP SECURITY)
When organizational roles change, API permissions evolve, or debugging requires temporary clearance, existing security rules and field masks can be revoked using DROP SECURITY.
Dropping an access control policy
To delete a named security policy from a bucket, specify the policy name and target bucket:
CleaveQLExample · Remove security policy
DROP SECURITY "lvl" ON docsThe policy rule is removed from the bucket's active policy catalog, and subsequent queries on docs no longer enforce that clearance condition.
Removing a field mask
Dynamic field masks registered via MASK are also removed using DROP SECURITY targeting the masked field name:
CleaveQLExample · Remove field mask
DROP SECURITY "secret" ON docsOnce dropped, the secret field is returned in full JSON payloads for all callers whose read access is otherwise permitted.
Immediate cluster-wide effect
Because CleaveDB evaluates DLS policies dynamically inside the AST interpreter:
- No database reload or cache invalidation step is necessary.
- Active client connections immediately reflect the policy removal on their very next query.
- Audit logs retain the historical record of policy creation and removal for compliance auditing.
