I’m having trouble with setting up better security here for critical/confidential data.
I setup Tables with permissions for only myself to add/delete records.
I setup every Field with permissions for only specific people to update data in the fields they own.
Everyone else is set to “commenter” role (which is the most worthless feature btw) to allow them to read only but still have access to personal views.
my dilemmas:
-
Is there a way to not allow anyone to create share links or add users? I found out that some commenters and editors were able to add users or share links on their own without my approval, which is incredibly unsafe. Surely there must be a way to limit this to Creator role or disable for specific roles?
-
Is there a way to allow users to create personal views, but only with shown fields? For example if I setup a table with a lot of backend fields that I control, but only want users to see the shown fields. I still want them to be able to further filter or customize their views by arranging fields or hiding more fields, but I do NOT want them to be able to turn on fields I already have hidden unless they are creator for example.
I love Airtable, and excited to figure out Sync and such, but as I build in more users im struggling with data security and access controls. How are people overcoming this?
