Getting Started

Tutorial: Building with CleaveDB

Enforce Security Policies

The ENFORCE SECURITY command defines access rules for documents within a bucket. It evaluates conditions against document fields, session context variables (like my role or @user_id), and graph bond relationships.

Basic policy declaration

Name the policy, bind it to a target bucket, designate the operation scope (read, write, or all), and declare the predicate:

CleaveQLExample · Role-based admin access
ENFORCE SECURITY "adm" ON docs TO ALLOW all IF my role = "admin"

You can also use the keyword form ENFORCE SECURITY POLICY or the alias SHAPE POLICY interchangeably.

Read vs. write policy behavior

CleaveDB handles read and write evaluations with different semantics tailored for security:

  • Read Policies: If a read condition fails, the document is silently omitted from FIND and SCOOP results—preventing callers from inferring the existence of confidential records.
  • Write Policies: If a write condition fails on POUR or CHANGE, the operation immediately aborts with an error, preserving database integrity.

Attribute-based comparison

Gate access based on document attributes or user IDs:

CleaveQLExample · Security clearance level
ENFORCE SECURITY POLICY "lvl" ON docs TO ALLOW read IF level < 3

Or bind writes to document ownership:

CleaveQLExample · Owner-only write gate
ENFORCE SECURITY "own" ON docs TO ALLOW write IF owner = @user_id

Graph-Based Access Control (GBAC)

Because CleaveDB is a native graph database, access control can traverse relationships in real time:

CleaveQLExample · Graph-based relationship check
ENFORCE SECURITY "owner_only" ON "documents" TO ALLOW read IF bonded as "owner" to my user_id

The engine evaluates whether an active bond exists between the document and the caller's ID before granting read access.