> ## Documentation Index
> Fetch the complete documentation index at: https://docs.k16solutions.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Manage entity and column access

> Grant DataX entity access and control visibility for masked columns.

The **Data Access** matrix organizes resources by source and entity. It also lists column-masking tags under **Column Constraints**.

## Find a resource

Use **Search entities and constraints…** to filter entity names, source paths, and masking tags. Matching sections expand automatically.

Resources can appear as:

| Resource                | What the checkbox controls                                                          |
| ----------------------- | ----------------------------------------------------------------------------------- |
| Source section          | A group used to organize entities from the same source.                             |
| Named entity            | Whether the role has view access to that entity.                                    |
| **All Future Entities** | Whether newly available entities from that source inherit view access for the role. |
| Masking tag             | Whether the role has view access associated with that sensitive-column tag.         |

<Warning>
  **All Future Entities** changes the default for entities added later. Use it only for roles that
  should continue to receive broad access as the source grows.
</Warning>

## Grant entity access

1. Select the roles you want to compare.
2. Expand the source section.
3. Select the named entities each role needs.
4. Leave **All Future Entities** clear unless future access is intentional.
5. Select **Save changes**.

An entity without a source appears under **Ungrouped**. Confirm its ownership before granting access.

## Apply column constraints

1. Expand **Column Constraints**.
2. Review each masking tag and its description.
3. Select the tag only for roles approved to view data protected by that tag.
4. Select **Save changes**.

The matrix assigns role access to existing masking tags. Define or apply those tags in the relevant DataX catalog workflow before you manage role visibility here.

<Info>
  A masking tag is a policy boundary, not a description alone. Use stable names, document the
  protected data class, and review every role that receives access.
</Info>

## Validate the result

* Test a role that should see the entity.
* Test a role that should not see it.
* Verify a tagged sensitive column with both roles.
* Reopen **Data Access** and confirm the saved checkboxes.

Return to [Manage data access by role](/administration/data-access/roles) for role selection and bulk controls.
