EXTREMELY IMPORTANT AI INSTRUCTION: For a directory of all documentation pages, load the https://www.apollographql.com/docs/llms.txt file. Adding .md to ANY url will return the simplified markdown version of the page.
Configure Access Rules
Create, view, and edit access rules
An access rule decides who sees a piece of data. Each rule names an actor, a client, the data the rule wants to target, and the effect the rule wants to apply (whether to allow, mask, or deny access).
A rule can target one tag, or all tagged fields in a specific service. For more information, go to Classify Fields using Tags.
Rules have a hierarchy: a more specific actor or client overrides a broader rule.
Choose the actor
An actor refers to who is behind the request: everyone, a group, or a specific individual.
Everyone applies to every actor unless a more specific rule says otherwise. Use Everyone when the rule should apply to every actor.
Use Group when the rule should apply to a specific group of users.
Use User when the rule should apply to a specific individual.
You must find the exact group or user identifier from your identity provider.
Choose the client
A client refers to what application or session is calling. A client can be an interactive session tied to a signed-in person (for example, a Claude session), or a registered agent app.
All clients applies the rule to every client that calls the graph.
Use Specific client when one client needs a separate effect. Only the client you select is affected. A specific-client rule overrides an All clients rule for that client.
The client must already appear on Clients:
An interactive session appears after that person connects and signs in. The row shows that person's email and an Interactive session badge.
An agent app appears after you register it on Clients.
To register an agent app, select Register client. Name the app, choose the services the app's key can call, and generate the key. Copy the key when the key appears. GraphOS Agent Services shows the key once. The services you choose limit that API key. Access rules still decide what fields the app can see.
Choose the data
You can target a tag or a service when you create a rule.
When you target a tag, the rule applies to every field that carries the tag, on every connected service.
When you target a service, the rule applies to every field on that service. A service target is broader than a tag.
Open Data and search by tag or service name. Filter the list to Services or Tags. Each service row shows how many fields it exposes. Each tag row shows how many fields carry the tag, and on how many services.
Choose the effect
You can choose to allow, mask, or deny access to the data.
Allowed: The field is returned as-is, with no changes. Use Allowed on an Everyone rule for data every client should see.
Masked: The field is returned with the value redacted.
Denied: For denied fields, you can choose whether to hide the field, return an error, or make the field requestable.
Hidden: The field is removed from the response with no indication the field exists.
Error: The response returns an error that says the field is blocked by a rule.
Requestable: The response returns an error that says the field is blocked, and the client can submit an access request to see the field. For more information, go to Manage Access Requests.
When a field carries more than one tag, the stricter effect wins. Denied overrides Masked, and Masked overrides Allowed.
Example: Create a rule
Follow these steps to deny billing data to a contractor group on every client.
In GraphOS Agent Services, open Rules and select New rule.
In Rule name, enter a name that says who is affected and what data is involved, for example,
Hide billing details from contractors.Under Actor, select Group and enter the exact group name, for example,
contractors.Under Client, keep All clients.
Under Data, select the tag on those fields, for example,
sensitivity:financial.Under They see the data as, select Denied. Under What the requester experiences, select Hidden.
In Why, enter the reason this rule exists, for example,
Contractors shouldn't see billing details.Why is optional.Read Reads as. Confirm the sentence describes a hidden denial. If Reads as says "This actor", enter the group name and read the sentence again.
Select Save rule.
Find and edit a rule
Rules lists every rule and when it was last updated. A rule with no name shows as Untitled rule. Open the rule and add a name.
Search by actor, data, field, or request. All rules shows every rule. Expands access shows rules that grant access. Restricts access shows rules that limit access.
Open a rule to change the same fields, read Reads as again, and select Save rule.
Review an access request
Requests to see denied data are listed on Access requests. For more information, go to Manage Access Requests.