A single filter handles most permission rules: a sales rep sees records where the region is North, a manager sees records where the status is Approved.
Real access rules are rarely that tidy. You want the rep to see records in their region or records they created, but only where the deal is still open. C
ondition groups let you express that, by nesting sets of conditions with their own all-or-any logic.
Note: Condition groups are available on the Lark Pro and Enterprise plans. On other plans you can still filter record permissions, but with a single flat list of conditions rather than nested groups.
What a Condition Group Actually Is
When you scope record permissions, you build a filter.
A plain filter is a flat list, and every condition in it joins with the same operator: either all of them must be true, or any one of them will do.
A condition group is a bracket around part of that list.
Conditions inside the group are evaluated together against their own all-or-any rule, then the group as a whole is evaluated against the outer rule.
That nesting is what makes mixed logic possible:
- Flat filter: Region is North AND Status is Open. Simple, but you cannot introduce an “or” without applying it to everything.
- With a condition group: Status is Open AND (Region is North OR Owner is the current member). The bracket keeps the “or” contained.
Without grouping, that second rule is impossible to write. Make the whole filter “any” and the Status check stops mattering; make it “all” and the rep only sees records that are both in their region and owned by them.
Where to Find the Setting
Condition groups appear wherever you scope records by condition, which is inside record permissions on the Data tab of the advanced permissions page.
- Open the base and click Advanced Permissions in the upper-right corner.
- Select the role you want to configure, then pick a table on the Data tab.
- Set the table permission to Can edit or View only, then expand Record permissions under Specific permissions.
- Under Records that can be edited and deleted, or Records that can be viewed, choose Records that match specific conditions.
The filter panel gives you two buttons. Add condition appends another line to the current list. Add Condition Group creates a nested bracket with its own conditions and its own all-or-any setting.
Building a Nested Rule
Work from the outside in. Decide what must always be true, then bracket the alternatives.
- Add the conditions that apply universally, and set the outer rule to require all of them.
- Click Add Condition Group.
- Inside the group, add the alternatives and set the group’s rule to require any of them.
- Repeat if you need more than one bracket.
- Save, or use Save and Preview to view the base as a member of that role before committing.
Tip: Previewing matters more with grouped conditions than with flat ones. Nested logic is easy to get subtly wrong, and the failure mode is silent: the role simply sees too much or too little, with no error to tell you.
Two Scopes, Configured Separately
Record permissions split what a role can edit and delete from what it can view, and each takes its own filter.
This is deliberate and worth using.
A common pattern for a sales team:
- Editable records: Status is Open AND (Owner is the current member OR Region is the member’s region).
- Viewable records: All records, so reps keep visibility of the wider pipeline.
The result is a team that can see everything and change only their own live deals.
Important: Whatever you build here still sits under the table permission. Set the table to View only and no condition group will grant edit rights. If your filter appears to be ignored, check the table-level setting first.
Practical Use Cases for SMEs and Startups
- Sales pipeline: Reps edit open deals they own or that fall in their territory, while seeing the full pipeline.
- Support queue: Agents edit tickets assigned to them or unassigned tickets in their product area, but not closed ones.
- Approvals: Department heads edit records for their own cost centre where the status is still Pending.
- Contractor access: An external role edits only records tagged to its project and marked active.
- Regional operations: Branch managers work on records for their branch or any record flagged as urgent, regardless of branch.
Frequently Asked Questions (FAQ)
What is a condition group in Lark Base permissions?
It is a nested set of conditions inside a record permission filter. The group has its own rule about whether all or any of its conditions must be met, and the group as a whole is then evaluated against the outer filter’s rule.
Why would I need one instead of a normal filter?
A flat filter applies one operator to every condition, so you cannot mix “and” with “or”. Grouping brackets part of the logic, letting you write rules such as status is open and either the owner or the region matches.
Which Lark plans support condition groups?
Pro and Enterprise. Other plans can still restrict records by condition, but only as a single flat list.
Can I set different conditions for viewing and for editing?
Yes, and it is usually the right approach. Records that can be edited and deleted takes one filter, records that can be viewed takes another, so a role can see broadly while editing narrowly.
Why is my condition group not restricting anything?
The most common cause is the table permission above it. Specific permissions can never exceed the table-level setting, so check that first. It is also worth confirming the group’s own all-or-any setting, since “any” with a broad condition inside will let most records through.
How do I test a permission filter before applying it?
Use Save and Preview instead of saving directly. That opens the base as a chosen collaborator so you can confirm which records the role can actually reach.
Can I nest a condition group inside another condition group?
The panel is designed around one level of grouping inside the main filter, which covers most access rules. If you find yourself wanting deeper nesting, it is usually a sign the rule would be simpler as a separate role.
Writing Access Rules That Match How Your Team Works
Most permission setups end up approximate because the tool only allowed a straight list of conditions, so somebody rounded the rule up or down.
Condition groups remove that compromise.
Write the rule the way you would say it out loud, bracket the alternatives, then preview it as the person who has to live with it.
Ready to Power Your Business with Lark?
Lark Base is just one part of an all-in-one platform that brings messaging, meetings, documents, approvals, and automations together for your entire team.
As the Platinum Partner for Lark in Malaysia, Exabytes offers tailored Lark plans, hands-on onboarding, and dedicated local support to help your team give everyone exactly the access they need.



















