# Globals Access Control

Source: https://payloadcms.com/docs/beta/access-control/globals

Global Access Control is [Access Control](/docs/v4/access-control/overview.md) used to restrict access to [Global](/docs/v4/configuration/globals.md) Documents, as well as what they can and cannot see within the [Admin Panel](/docs/v4/admin/overview.md) as it relates to that Global.

To add Access Control to a Global, use the `access` property in your [Global Config](/docs/v4/configuration/globals.md):

```ts
import type { GlobalConfig } from 'payload'

export const GlobalWithAccessControl: GlobalConfig = {
  // ...
  access: {
    // highlight-line
    // ...
  },
}
```

## Config Options

Access Control is specific to the operation of the request.

To add Access Control to a [Global](/docs/v4/configuration/globals.md), use the `access` property in the [Global Config](/docs/v4/configuration/globals.md):

```ts
import { GlobalConfig } from 'payload'

const GlobalWithAccessControl: GlobalConfig = {
  // ...
  // highlight-start
  access: {
    read: ({ req: { user } }) => {...},
    update: ({ req: { user } }) => {...},
    validate: ({ req: { user } }) => {...},

    // Version-enabled Globals only
    readVersions: () => {...},
  },
  // highlight-end
}

export default Header
```

The following options are available:

| Function       | Allows/Denies Access                                                                                              |
| -------------- | ----------------------------------------------------------------------------------------------------------------- |
| **`read`**     | Used in the `findOne` Global operation. [More details](#read).                                                    |
| **`update`**   | Used in the `update` Global operation. [More details](#update).                                                   |
| **`validate`** | Optionally overrides `update` access for [on-demand validation](/docs/v4/validation/overview.md#access-control-and-hooks). |

If a Global supports [Versions](/docs/v4/versions/overview.md), the following additional options are available:

| Function           | Allows/Denies Access                                                                                                                                   |
| ------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **`readVersions`** | Used to control who can read versions, and who can't. Will automatically restrict the Admin UI version viewing access. [More details](#read-versions). |

### Read

Returns a boolean result or optionally a [query constraint](/docs/v4/queries/overview.md) which limits who can read this global based on its current properties.

To add read Access Control to a [Global](/docs/v4/configuration/globals.md), use the `access` property in the [Global Config](/docs/v4/configuration/globals.md):

```ts
import { GlobalConfig } from 'payload'

const Header: GlobalConfig = {
  // ...
  // highlight-start
  access: {
    read: ({ req: { user } }) => {
      return Boolean(user)
    },
  },
  // highlight-end
}
```

The following arguments are provided to the `read` function:

| Option     | Description                                                                                                                   |
| ---------- | ----------------------------------------------------------------------------------------------------------------------------- |
| **`req`**  | The [Request](https://developer.mozilla.org/en-US/docs/Web/API/Request) object containing the currently authenticated `user`. |
| **`slug`** | The slug of the Global being accessed.                                                                                        |

### Update

Returns a boolean result or optionally a [query constraint](/docs/v4/queries/overview.md) which limits who can update this global based on its current properties.

To add update Access Control to a [Global](/docs/v4/configuration/globals.md), use the `access` property in the [Global Config](/docs/v4/configuration/globals.md):

```ts
import { GlobalConfig } from 'payload'

const Header: GlobalConfig = {
  // ...
  // highlight-start
  access: {
    update: ({ req: { user }, data }) => {
      return Boolean(user)
    },
  },
  // highlight-end
}
```

The following arguments are provided to the `update` function:

| Option     | Description                                                                                                                   |
| ---------- | ----------------------------------------------------------------------------------------------------------------------------- |
| **`req`**  | The [Request](https://developer.mozilla.org/en-US/docs/Web/API/Request) object containing the currently authenticated `user`. |
| **`data`** | The data passed to update the global with.                                                                                    |
| **`slug`** | The slug of the Global being accessed.                                                                                        |

### Read Versions

If the Global has [Versions](/docs/v4/versions/overview.md) enabled, the `readVersions` Access Control function determines whether or not the currently logged in user can access the version history of a Document.

If `readVersions` is not configured, Payload uses the Global's `read` Access Control. Boolean results are preserved, and query constraints are automatically adjusted to target fields within the stored version document.

To add Read Versions Access Control to a Global, use the `readVersions` property in the [Global Config](/docs/v4/configuration/globals.md):

```ts
import type { GlobalConfig } from 'payload'

export const GlobalWithVersionsAccess: GlobalConfig = {
  // ...
  access: {
    // highlight-start
    readVersions: ({ req: { user } }) => {
      return Boolean(user)
    },
    // highlight-end
  },
}
```

> **Note:** When you explicitly configure `readVersions`, returning a
> [Query](/docs/v4/queries/overview.md) will apply the constraint to the [`versions`
> collection](/docs/v4/versions/overview.md#database-impact), not the original Global.

The following arguments are provided to the `readVersions` function:

| Option     | Description                                                                                                                   |
| ---------- | ----------------------------------------------------------------------------------------------------------------------------- |
| **`req`**  | The [Request](https://developer.mozilla.org/en-US/docs/Web/API/Request) object containing the currently authenticated `user`. |
| **`slug`** | The slug of the Global being accessed.                                                                                        |
