# Field-level Access Control

Source: https://payloadcms.com/docs/beta/access-control/fields

Field Access Control is [Access Control](/docs/v4/access-control/overview.md) used to restrict access to specific [Fields](/docs/v4/fields/overview.md) within a Document.

To add Access Control to a Field, use the `access` property in your [Field Config](/docs/v4/fields/overview.md):

```ts
import type { Field } from 'payload'

export const FieldWithAccessControl: Field = {
  // ...
  access: {
    // highlight-line
    // ...
  },
}
```

> **Note:** Field Access Control does not support returning
> [Query](/docs/v4/queries/overview.md) constraints like [Collection Access
> Control](/docs/v4/access-control/collections.md) does.

## Config Options

Access Control is specific to the operation of the request.

To add Access Control to a Field, use the `access` property in the [Field Config](/docs/v4/fields/overview.md):

```ts
import type { CollectionConfig } from 'payload';

export const Posts: CollectionConfig = {
  slug: 'posts',
  fields: [
    {
      name: 'title',
      type: 'text',
      // highlight-start
      access: {
        create: ({ req: { user } }) => { ... },
        read: ({ req: { user } }) => { ... },
        update: ({ req: { user } }) => { ... },
        validate: ({ req: { user } }) => { ... },
      },
      // highlight-end
    };
  ],
};
```

The following options are available:

| Function       | Purpose                                                                                                                                       |
| -------------- | --------------------------------------------------------------------------------------------------------------------------------------------- |
| **`create`**   | Allows or denies the ability to set a field's value when creating a new document. [More details](#create).                                    |
| **`read`**     | Allows or denies the ability to read a field's value. [More details](#read).                                                                  |
| **`update`**   | Allows or denies the ability to update a field's value. [More details](#update).                                                              |
| **`validate`** | Optionally overrides `update` access for candidate field data during [on-demand validation](/docs/v4/validation/overview.md#access-control-and-hooks). |

### Create

Returns a boolean which allows or denies the ability to set a field's value when creating a new document. If `false` is returned, any passed values will be discarded.

**Available argument properties:**

| Option            | Description                                                                                                                  |
| ----------------- | ---------------------------------------------------------------------------------------------------------------------------- |
| **`req`**         | The [Request](https://developer.mozilla.org/en-US/docs/Web/API/Request) object containing the currently authenticated `user` |
| **`collection`**  | The collection config that owns the field (present only for collection-owned fields).                                        |
| **`global`**      | The global config that owns the field (present only for global-owned fields).                                                |
| **`data`**        | The full data passed to create the document.                                                                                 |
| **`siblingData`** | Immediately adjacent field data passed to create the document.                                                               |
| **`blockData`**   | The nearest parent block row data when this field is inside a block.                                                         |

### Read

Returns a boolean which allows or denies the ability to read a field's value. If `false`, the entire property is omitted from the resulting document.

**Available argument properties:**

| Option            | Description                                                                                                                  |
| ----------------- | ---------------------------------------------------------------------------------------------------------------------------- |
| **`req`**         | The [Request](https://developer.mozilla.org/en-US/docs/Web/API/Request) object containing the currently authenticated `user` |
| **`collection`**  | The collection config that owns the field (present only for collection-owned fields).                                        |
| **`global`**      | The global config that owns the field (present only for global-owned fields).                                                |
| **`id`**          | `id` of the document being read                                                                                              |
| **`doc`**         | The full document data.                                                                                                      |
| **`siblingData`** | Immediately adjacent field data of the document being read.                                                                  |
| **`blockData`**   | The nearest parent block row data when this field is inside a block.                                                         |

### Update

Returns a boolean which allows or denies the ability to update a field's value. If `false` is returned, any passed values will be discarded.

If `false` is returned and you attempt to update the field's value, the operation will **not** throw an error however the field will be omitted from the update operation and the value will remain unchanged.

**Available argument properties:**

| Option            | Description                                                                                                                  |
| ----------------- | ---------------------------------------------------------------------------------------------------------------------------- |
| **`req`**         | The [Request](https://developer.mozilla.org/en-US/docs/Web/API/Request) object containing the currently authenticated `user` |
| **`collection`**  | The collection config that owns the field (present only for collection-owned fields).                                        |
| **`global`**      | The global config that owns the field (present only for global-owned fields).                                                |
| **`id`**          | `id` of the document being updated                                                                                           |
| **`data`**        | The full data passed to update the document.                                                                                 |
| **`siblingData`** | Immediately adjacent field data passed to update the document with.                                                          |
| **`doc`**         | The full document data, before the update is applied.                                                                        |
| **`blockData`**   | The nearest parent block row data when this field is inside a block.                                                         |
