> For the complete documentation index, see [llms.txt](https://docs.jetadmin.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.jetadmin.io/access-and-sharing/app-and-data-permissions/record-access.md).

# Restrict access to records

Define which records an authenticated user may read or change. Enforce that decision in the data-access layer that handles the request.

## Define the rule

For a customer portal, an example policy is: a user may access a ticket only when the ticket's customer ID matches the user's trusted customer ID.

Before implementing that policy, identify:

* Where the authenticated identity comes from.
* Where its customer ID is stored and who can edit it.
* Which queries and actions access tickets.
* How missing or invalid customer IDs are handled.

## Apply the rule consistently

Cover list queries, individual record reads, search, counts, exports, create, update, delete, and any workflows that operate on the same data. A page filter alone does not establish authorization for these other paths.

For writes, verify both the existing record's ownership and any submitted ownership values. Do not let a user assign a new record to an unauthorized customer or move an existing record outside their permitted scope.

The exact implementation depends on the resource, API, and app architecture. Use its supported authorization mechanism and test the result; do not infer enforcement from generated UI code.

## Verify with two users

Create test identities for two different customers and test records for each. Confirm each identity can access its own permitted records and cannot read or modify the other's records, including a direct record request.

Repeat with a missing customer ID. The intended restricted behavior should be explicit. Use [the test matrix](/access-and-sharing/overview/test-access.md) to record results and [customer data isolation](/access-and-sharing/app-and-data-permissions/customer-data-isolation.md) for a complete portal review.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://docs.jetadmin.io/access-and-sharing/app-and-data-permissions/record-access.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `build a script that syncs our docs to a CMS` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
