Getting Started

Tutorial: Building with CleaveDB

Remove Policies (DROP SECURITY)

When organizational roles change, API permissions evolve, or debugging requires temporary clearance, existing security rules and field masks can be revoked using DROP SECURITY.

Dropping an access control policy

To delete a named security policy from a bucket, specify the policy name and target bucket:

CleaveQLExample · Remove security policy
DROP SECURITY "lvl" ON docs

The policy rule is removed from the bucket's active policy catalog, and subsequent queries on docs no longer enforce that clearance condition.

Removing a field mask

Dynamic field masks registered via MASK are also removed using DROP SECURITY targeting the masked field name:

CleaveQLExample · Remove field mask
DROP SECURITY "secret" ON docs

Once dropped, the secret field is returned in full JSON payloads for all callers whose read access is otherwise permitted.

Immediate cluster-wide effect

Because CleaveDB evaluates DLS policies dynamically inside the AST interpreter:

  • No database reload or cache invalidation step is necessary.
  • Active client connections immediately reflect the policy removal on their very next query.
  • Audit logs retain the historical record of policy creation and removal for compliance auditing.