← Blog

Governance · 2 July 2026 · 8 min read

Governance for content teams: roles, permission sets and field-level security

How object-level roles, grant and restrict permission sets, record conditions and field-level security combine into a single, auditable access decision.

Platform team · Security

A layered decision

Access is resolved in a fixed order: the role baseline, then permission sets that widen access, then sets that cap it, then schema policies where a deny always wins. Because the order is fixed, an access question has one answer and one explanation.

Field-level security

Read and write projections are computed per record, so a reviewer can see a price while an editor cannot, without a bespoke endpoint. Secrets such as password fields are hashed on write and stripped from every read surface.

Evidence, not assumptions

Every mutation and transition lands in an append-only audit log with actor, source, request id and diff, and every entry keeps an immutable revision snapshot. Governance reviews then work from records rather than recollection.

rbacsecurityaudit