# Granular Access Control

**URL:** <https://forum.solidproject.org/t/granular-access-control/1665>\
**Category:** General Discussion\
**Created:** [April 10, 2019, 10:08pm UTC](https://forum.solidproject.org/t/granular-access-control/1665 "2019-04-10T22:08:43Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![markjspivey](https://avatars.discourse-cdn.com/v4/letter/m/82dd89/32.png) [@markjspivey](https://forum.solidproject.org/u/markjspivey)\
**Post date:** [April 10, 2019, 10:08pm UTC](https://forum.solidproject.org/t/granular-access-control/1665/1 "2019-04-10T22:08:43Z")

</div>

What is an example best practice for managing granular (infra-document) Web Access Control to SOLID resources/files?

For instance, given my profile is one resource, if I want to make my name public, but my organization name private.

---

<div class="post-metadata">

**Author:** ![happybeing](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.solidproject.org/happybeing/32/59_2.png) [@happybeing](https://forum.solidproject.org/u/happybeing)\
**Post date:** [April 11, 2019, 7:32am UTC](https://forum.solidproject.org/t/granular-access-control/1665/2 "2019-04-11T07:32:21Z")

</div>

I think the limit of granularity is a file, so you would put your organisation in a separate file (along with other restricted information) and link to that from your public profile.

---

<div class="post-metadata">

**Author:** ![aveltens](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.solidproject.org/aveltens/32/3987_2.png) [@aveltens](https://forum.solidproject.org/u/aveltens)\
**Post date:** [April 11, 2019, 7:44am UTC](https://forum.solidproject.org/t/granular-access-control/1665/3 "2019-04-11T07:44:24Z")

</div>

> [@happybeing](#):
>
> I think the limit of granularity is a file, so you would put your organisation in a separate file (along with other restricted information) and link to that from your public profile.

Exactly. This is called [Extended Profile](https://github.com/solid/solid-spec/blob/master/solid-webid-profiles.md#extended-profile) and the links should be `owl:sameAs` or `rdfs:seeAlso`.

---

<div class="post-metadata">

**Author:** ![markjspivey](https://avatars.discourse-cdn.com/v4/letter/m/82dd89/32.png) [@markjspivey](https://forum.solidproject.org/u/markjspivey)\
**Post date:** [April 11, 2019, 3:18pm UTC](https://forum.solidproject.org/t/granular-access-control/1665/4 "2019-04-11T15:18:33Z")

</div>

Ok thanks, and to generalize this case, would this mean you would need to create one file per triple in order to assign access control per triple, instead of one file but access control at fragment level?

---

<div class="post-metadata">

**Author:** ![aveltens](https://dub1.discourse-cdn.com/flex017/user_avatar/forum.solidproject.org/aveltens/32/3987_2.png) [@aveltens](https://forum.solidproject.org/u/aveltens)\
**Post date:** [April 11, 2019, 3:38pm UTC](https://forum.solidproject.org/t/granular-access-control/1665/5 "2019-04-11T15:38:39Z")

</div>

At least NSS does only have access control at file level. I am not sure if this is required by the spec. Servers that do not rely on the file system might indeed have a triple based access control, imho.

---

<div class="post-metadata">

**Author:** ![markjspivey](https://avatars.discourse-cdn.com/v4/letter/m/82dd89/32.png) [@markjspivey](https://forum.solidproject.org/u/markjspivey)\
**Post date:** [April 11, 2019, 10:17pm UTC](https://forum.solidproject.org/t/granular-access-control/1665/6 "2019-04-11T22:17:57Z")

</div>

got it, thanks! I was also reviewing the PIXOLID thread on how it is set up and it looks like each photo is a separate file so I can see how that would work.
