Find a resource
Use Search entities and constraints… to filter entity names, source paths, and masking tags. Matching sections expand automatically. Resources can appear as:Grant entity access
- Select the roles you want to compare.
- Expand the source section.
- Select the named entities each role needs.
- Leave All Future Entities clear unless future access is intentional.
- Select Save changes.
Apply column constraints
- Expand Column Constraints.
- Review each masking tag and its description.
- Select the tag only for roles approved to view data protected by that tag.
- Select Save changes.
A masking tag is a policy boundary, not a description alone. Use stable names, document the
protected data class, and review every role that receives access.
Validate the result
- Test a role that should see the entity.
- Test a role that should not see it.
- Verify a tagged sensitive column with both roles.
- Reopen Data Access and confirm the saved checkboxes.