Step 12 · Control access

Control who sees what

Set up FireAI Data Guard for row-level access. Link each user's email to a code in your data, protect fact tables, write scopes, group them into data roles, and test before going live.

Updated September 30, 2026

Only needed if different people should see different data. Everyone opens the same dashboard, but a store manager sees only their shop and the CFO sees everything. FireAI calls this Data Guard.

The most technical step in this guide

Follow it exactly, test it (action 16) before telling anyone it is ready, and ask the FireAI team to check it with you the first time. A mistake here can show someone data they should not see.

You will need List 3 from Step 0. You will also need to know which table lists your staff and their shop codes. If you do not have such a table, ask the FireAI team to create one before you start.

The step has five parts:

  1. Switch on Data Guard and link emails to codes
  2. Choose the tables to protect
  3. Write the rules
  4. Group rules into roles
  5. Give people roles, then test

FireAI needs to know, for each person who signs in, their code in your data (such as their shop number).

  1. Select Settings, then Access & Roles.
  2. At the top right, turn on Enable Data Guard. A box opens.
  3. Fill it in:
Box What to put
Datasource Your data source from Step 2
Identifier Name A short name for the code, for example shop_no
Variables Supported email
Identifier Query The template below, with the capital words changed
Description Anything that helps you later, for example "Finds each manager's shop from their email"
Copy this exactly, then change only the words in CAPITALS
SELECT SHOP_COLUMN FROM STAFF_TABLE WHERE EMAIL_COLUMN = {{email}}
Replace With Our example
STAFF_TABLE The table that lists your staff store_managers
SHOP_COLUMN The column holding each person's code shop_no
EMAIL_COLUMN The column holding their email email
  1. Select Create Config.

You should now see

Data Guard Enabled at the top right, and two new tabs: Fact Tables and Data Roles & Scopes.

Never select Delete Config by accident

Delete Config (in the menu beside Data Guard Enabled) switches Data Guard off completely. It cannot be undone from the app.

Choose the tables to protect

  1. Open the Fact Tables tab and add a new row.
  2. Under Table Name, pick your sales table (sales_master). Under Column Name, pick the column that identifies each row, usually an ID or invoice number. If you are not sure, ask the FireAI team. Save.
  3. Repeat for every table your dashboards use.

Unlisted tables are not protected

Any table you leave out here is not protected: everyone sees all of it, and nothing warns you.

Write the rules

A rule (FireAI calls it a scope) says which rows someone may see. Make one rule per kind of person in List 3.

  1. Open the Data Roles & Scopes tab. Under Scopes, select Create Scope.
  2. Rule for store managers (see only their shop). Fill in the boxes:

Sample table. sales_master and SHOPNO are example names: use your own table and the column that holds each person's code. Type =, IN, '{{identifier}}' and [all] exactly as shown.

Box What to type
Scope Name Store - Own Shop
Predicate Column SHOPNO (the column in your sales table holding the shop code)
Predicate Operation =
Predicate Query '{{identifier}}' including the single quote marks
Fact table Pick sales_master, then the column SHOPNO
  1. Save. Select Create Scope again for regional managers (see every shop in their region):
Box What to type
Scope Name Region - Own Shops
Predicate Column SHOPNO
Predicate Operation IN
Predicate Query The template below, with the capital words changed
Fact table Pick sales_master, then the column SHOPNO
Copy this exactly, then change only the words in CAPITALS
(SELECT SHOP_COLUMN FROM REGION_TABLE WHERE MANAGER_COLUMN = '{{identifier}}')

Replace REGION_TABLE with the table that links shops to regions, and the two column names with its columns. The FireAI team can give you these names.

  1. Rule for head office (see everything): Scope Name "All Data", and in Predicate Column type [all] including the square brackets. Save.

Group rules into roles

  1. Scroll to Data Roles and select Create Data Role.
  2. Name it store_manager, pick the rule Store - Own Shop, and click the rule once to make it the Default. Save.
  3. Make regional_manager (rule Region - Own Shops) and head_office (rule All Data) the same way.

Give each person their role, then test

  1. Open the Users tab. For each person in List 3, fill in their code, their Data Role and Allowed Scopes, choose a default, and select Save on their row.

Sample table. Fill it in for your own people from List 3.

Person shop_no Data role
priya@acme.com S-104 store_manager
arun@acme.com R-WEST regional_manager
cfo@acme.com HO head_office
  1. Test before telling anyone. Ask Priya (or a colleague using a test account set up the same way) to sign in and open the sales dashboard.

You should now see

Priya sees only shop S-104. The CFO sees every shop. If Priya sees everything or nothing, see If something goes wrong.

Tick these before the next step

  • Every table my dashboards use is under Fact Tables
  • Every person in List 3 has a code, a role and a default rule
  • I have tested one restricted person and one head office person

Next step