Tutorial: Building with CleaveDB
Field Masking (MASK)
In many healthcare, financial, and enterprise domains, users need access to documents without seeing sensitive fields (such as salaries, credit cards, or social security numbers). Rather than creating duplicated redacted views or blocking document access completely, CleaveDB provides Dynamic Field Masking via MASK.
Masking sensitive fields
Specify the field name, target bucket, and condition under which the field should be stripped from query outputs:
MASK "salary" ON staff IF my role = "viewer"When an authenticated viewer executes FIND staff, the document is returned in full, but the salary key is stripped from the JSON response before leaving the database.
Negative role conditions
Use negative conditions (IS NOT or !=) to permit only specific privileged roles:
MASK "ssn" ON "patients" IF my role IS NOT "doctor"Anyone other than authenticated doctors will receive patient records with the ssn field completely omitted.
Attribute-based masking
You can also mask fields based on attributes within the document itself:
MASK "secret" ON docs IF level > 3Documents with high clearance levels automatically redact their confidential sections when queried.
