---
title: How do I Implement Access Control? - TrueVault
description: How do I Implement Access Control? - TrueVault
---

<https://safe.truevault.com/?hsLang=en>

- [CCPA](https://safe.truevault.com/learn/ccpa/what-is-the-ccpa)
- [GDPR Compliance](https://safe.truevault.com/gdpr-guide)
- [Personal Data](https://safe.truevault.com/learn/what-is-personal-data)
- [DSAR](https://safe.truevault.com/learn/explaining-gdpr-data-subject-requests)
- [HIPAA](https://safe.truevault.com/learn/hipaa)
- [HIPAA Compliance](https://safe.truevault.com/blog/hipaa-compliance-checklist-download.html)
- [Personally Identifiable Information](https://safe.truevault.com/blog/what-is-phi)
- [PHI](https://safe.truevault.com/protected-health-information)

- [Resources](https://safe.truevault.com/learn/) 
    - [Resource Center](https://safe.truevault.com/learn/)
    - [TrueVault Safe](https://safe.truevault.com/help/truevault-safe)
- [About](https://safe.truevault.com/about-us)
- [Contact](https://safe.truevault.com/contact-us)
- [Careers](https://careers.truevault.com/)

- Solutions 
    - [GDPR Compliance](https://safe.truevault.com/solutions/gdpr-compliance)
    - [HIPAA Compliance](https://safe.truevault.com/hipaa-compliance)
    - [For Applications](https://safe.truevault.com/solutions/application-compliance)
    - [For Data Exchanges](https://safe.truevault.com/solutions/data-exchange-compliance)
- [Developers](https://safe.truevault.com/resources/index)
- [Pricing](https://safe.truevault.com/safe-pricing)
- [Blog](https://safe.truevault.com/blog)
- [Login](https://console.truevault.com/login)
- [Get Started](https://safe.truevault.com/get-started)

Resources

- [Home](https://safe.truevault.com/homepage-v3?hsLang=en)
- [Resources](https://safe.truevault.com/resources/index?hsLang=en)
- How do I Implement Access Control

# How do I Implement Access Control?

You can restrict users’ access to data stored in TrueVault with granular Group Policies. This is a critical component of the security of your application, and we recommend enforcing minimal access for every user. Read more in our [Access Control Best Practices](https://safe.truevault.com/resources/developer/what-are-access-control-best-practices?hsLang=en) guide.

## Policies

Policies are composed of two components:

1. **Resources:** A list of resource specifiers that describe which Documents, Vaults, BLOBs, Users, or Groups the Policy grants access to.
2. **Actions:** A list of actions the policy authorizes for the specified resources.

For example, a resource could be all documents in my “patient records” vault. Actions could grant full access (Create, Read, Update, Delete) or be more restrictive and only allow read-only access. Using TrueVault policy syntax, these policies would be expressed by the following (assuming the patient records vault had id `00000000-0000-0000-0000-00000000000`)

#### Full Access Policy

 

```
{
    "Resources":[
        "Vault::00000000-0000-0000-0000-000000000000::Document::"
        "Vault::00000000-0000-0000-0000-000000000000::Document::.*",
    ],
    "Activities":"CRUD"
}
```

*Note*: to create Document’s in a vault, the first resource is needed. To read/update/delete any Document in that vault, the second resources is needed. Check out the [policy access grid](https://docs.truevault.com/groups#access-grid) for the details.

 

#### Read Only Policy

```
{
    "Resources":[
        "Vault::00000000-0000-0000-0000-000000000000::Document::.*",
    ],
    "Activities":"R"
}
```

Each policy statement can have many resources and activities associated with it. Check out some [example policies](https://docs.truevault.com/groups#example-group-policies) or dig into the [policy access grid](https://docs.truevault.com/groups#access-grid) to get more details.

### Ownership

Some policies define explicit resources: Documents in this vault, this specific Document ID, all Users, etc. This can be useful, but can be verbose in some cases. To simplify your policies, we built ownership for a common use case: users can read and modify their *own* data. In this model, you assign an owner to each record and can create one group for all users that allows them to read/modify their own data, but nobody else’s. Read more in our [ownership guide](https://safe.truevault.com/resources/developer/how-do-i-make-sure-users-have-access-to-only-their-own-documents-and-blobs?hsLang=en).

## Groups

Groups are the glue that bring users and policies together. A group can have many policies in it. A user can belong to many groups, and a group can have many users in it.

For example, if you’re building a healthcare product you might have a few roles: patients, doctors, staff. You could create one group for each role: a patient’s group that uses [ownership](https://safe.truevault.com/resources/developer/how-do-i-make-sure-users-have-access-to-only-their-own-documents-and-blobs?hsLang=en) to limit acccess, a doctor’s group that allows access to all patient’s data, and an staff group that allows access to billing data but not health records. In this case, you may think the doctor’s group is a little too permissive, and we’d agree. Do doctor’s need to see every patient, or only the one’s their assigned to? If you can minimize their access, do so (read more on our [Access Control Best Practices](https://safe.truevault.com/resources/developer/what-are-access-control-best-practices?hsLang=en) guide).

To limit each doctor’s access, you could create a group-per-patient that allows access to that patient’s records. Then you could add a doctor to a patient’s group when they’re assigned to that patient.

Let’s look at the groups we’ve discussed in detail. If you were creating these groups through the [api](https://docs.truevault.com/groups#create-a-group) then you would want to specify the policies as a JSON Object. For the sake of this example, assume you have a “Patient Health Data” vault with id `00000000-0000-0000-0000-000000000000` and a “Patient Billing Data” vault with id `11111111-1111-1111-1111-111111111111`. Each group takes an array of policies when you create it, like the following.

#### Patient’s Group Policy

In this group, patients can Create, Read, Update, and Delete their *own* data.

```
[ 
    {
        "Resources":[
            "Vault::00000000-0000-0000-0000-000000000000::Document::$[Owner=self]"
            "Vault::11111111-1111-1111-1111-111111111111::Document::$[Owner=self]"
        ],
        "Activities":"CRUD"
    }
]
```

#### Staff Group Policy

Staff can view and update billing data, but cannot create see health data, create new patients, or delete anything.

```
[ 
    {
        "Resources":[
            "Vault::11111111-1111-1111-1111-111111111111::Document::.*"
        ],
        "Activities":"RU"
    }
]
```

#### Doctor’s Group for Patient:

Doctor’s in this group can see and modify all the data for a specific patient. For this example, say the patient has the id `aaaaaaaa-aaaa-aaaa-aaaa-aaaaaaaaaaaa`.

```
[ 
    {
        "Resources":[
            "Vault::00000000-0000-0000-0000-000000000000::Document::$[Owner=aaaaaaaa-aaaa-aaaa-aaaa-aaaaaaaaaaaa]"
            "Vault::11111111-1111-1111-1111-111111111111::Document::$[Owner=aaaaaaaa-aaaa-aaaa-aaaa-aaaaaaaaaaaa]"
        ],
        "Activities":"CRUD"
    }
]
```

### Latest Posts

## [Should Utah's Privacy Law Be on Your Radar?](https://safe.truevault.com/blog/utah-privacy-law-does-it-apply?hsLang=en)

 Phillip Walters  / November 17, 2022

## [Connecticut’s Privacy Law: Does It Apply to Your Business?](https://safe.truevault.com/blog/connecticut-privacy-law-does-it-apply?hsLang=en)

 Phillip Walters  / November 10, 2022

## [Global Privacy Control: A New Requirement for Compliance](https://safe.truevault.com/blog/global-privacy-control?hsLang=en)

 Phillip Walters  / November 7, 2022

### Mailing List

### Company

- [Blog](https://safe.truevault.com/blog)
- [Contact Us](https://safe.truevault.com/contact-us-2019)
- [Careers](https://truevault.workable.com)
- [HIPAA Compliance Checklist](https://safe.truevault.com/blog/hipaa-compliance-checklist-download.html)
- [PDF: Developers Guide to HIPAA compliance](https://my.leadpages.net/leadbox/14472b173f72a2%3A131fd12f8b46dc/5760820306771968/)

### Developers

- [Patterns](https://safe.truevault.com/patterns)
- [Documentation](https://docs.truevault.com/)
- [Quick Start Guide](https://safe.truevault.com/quick-start-guide)
- [Secure Infrastructure](https://safe.truevault.com/secure-infrastructure)
- [API Overview](https://safe.truevault.com/api-overview)

### Latest Posts

### Contact Us

201 Mission Street, 12th Floor  
 San Francisco, CA 94105  
 Email: [hello@truevault.com](mailto:hello@truevault.com)

2021 © All Rights Reserved. [Privacy Policy](https://privacy.truevault.com/privacy-policy) | [Terms of Service](https://safe.truevault.com/terms-of-service?hsLang=en)

- <https://www.facebook.com/truevault?fref=ts>
- <https://www.linkedin.com/company/truevault>
- <https://twitter.com/truevault>