Access protection for records is ensured by the access control of the basic system, PiSA cubes. Access protection makes it possible to define account policies for individual users or groups directly for a record. This is usually limited to the owner of the record.
Protection of records

Access mask for records
See also: Protection of records
Who can edit access attributes?
When creating a record, the current user automatically becomes its owner. Only they can modify group account policies in the access form. All other users are not granted write access to the permission definition.
If the owner restricts their own permissions for a record, these restricted permissions are valid with one exception: While the user is not allowed to modify or delete a record locked for them, they can still read it.
Note: When copying a record, the account policy of the source record is not copied. Only the new record owner who made the copy can change its account policy.
Records without read access
If no read permission is granted for records, the users concerned can only see the corresponding entries in forms and lists as asterisks (*****) in the subject.