Knowing that Lark Base has advanced permissions is one thing. Sitting in front of the settings panel and working out which of the four tabs controls what is another. This is the hands-on version: every screen you will touch, in the order you will touch it, from switching the feature on to locking down exports.
Note: Only the base owner and collaborators with manage permission can turn advanced permissions on and configure them. Which Lark plan you are on determines whether view, record and field permissions can be configured at all.
Step 1: Turn On Advanced Permissions
Open the base and click the Base advanced permissions icon in the upper-right corner.
In the window that opens, click Turn On Advanced Permissions.
If your base is still on the older permissions system, you will see a slightly different screen with a Try Now prompt to upgrade.
Important: While you are on the new permissions page and have not yet clicked Save, a Revert to Previous Version option sits in the lower-left corner. Once you save, that door closes and you cannot go back to the old page.
Step 2: Get Your Bearings on the Permissions Page
Roles run down the left-hand side, split into System roles (Owner, Administrator, Editor, Viewer) and Custom roles you create yourself. Select a role and its permissions appear on the right, organised into four tabs: Data, Dashboard, Automation and Others.
At the top you will also find a switch between Grant Access Through Sharing and Only Custom Roles Can Access, which decides whether people can reach the base through a share link at all.
Step 3: Set the Table Permission First
Everything else hangs off this. On the Data tab, pick a table and choose one of four levels:
- Can manage: Add, edit and delete every record, field and view. Because this is the ceiling, the specific permissions below are locked at their highest setting.
- Can edit: The useful one. You can then fine-tune records, fields and views underneath.
- View only: Read access, which you can narrow further.
- No access: The table disappears for that role.
Tip: Specific permissions can never exceed the table permission. Set the table to View only and no amount of fiddling below will grant edit rights. If a setting appears greyed out, this is usually why.
Step 4: Configure Record Permissions
With the table set to Can edit, expand Record permissions under Specific permissions.
First decide whether the role can add records and delete records. Then set which records they can edit and delete:
- All records: No restriction within the table.
- Records related to members themselves: Only records they created, or records where a person field names them.
- Records that match specific conditions: A filter you define, such as region or status.
If you picked anything other than All records, you then set what they can see separately under Records that can be viewed. The same three options apply, plus Only editable records if you want visibility and edit rights to match exactly.
This split is the whole point of record permissions. A sales rep might edit only their own deals but still see the full pipeline, or see only their own, whichever suits the team.
Step 5: Configure Field Permissions
Still on Can edit, expand Field permissions and choose Custom. You get a grid of every field with three checkboxes each: Can view all, Can add all and Can edit all.
This is how you hide a salary column from everyone except HR while leaving the rest of the employee table open.
Two fields resist restriction. The index field is always visible, and system fields (created by, modified by, date created and last modified date) are always visible and can never be made editable, since Lark fills them in itself.
Option permissions
Scroll down within the same Custom panel to Option permissions. Here you control whether the role can add, delete or edit the choices in single-option and multiple-option fields. Only fields the role can already edit appear as selectable.
Attachment download permissions
Below that sits Action permissions, listing every attachment field in the table. All roles can download attachments by default; deselect a field to stop them.
Important: Attachment downloads are governed by three settings at once. If Duplicate, download or print Base is unticked on the Others tab, this option cannot be selected at all. Separately, the general permission settings under Share then Permission settings control who can duplicate, print and download. A user has to clear both hurdles. And even then, they can only download from attachment fields they can see.
Step 6: Configure View Permissions
Expand View permissions to control which views a role sees and whether they can create new ones.
Choose All views or tick individual views under Specific views. Note that the two settings are mutually exclusive in one direction: pick Specific views and Can add, delete or edit views greys out.
Two behaviours worth knowing:
- Private views ignore visibility settings entirely. They stay visible only to their owner.
- If a role already cannot see some views, any new view is hidden from them by default. You have to grant access to each new view manually.
Step 7: Set Dashboard Visibility
Owner and Administrator always have edit permission for dashboards, and that cannot be changed. Every other role, including Editor, Viewer and any custom role, can only be set to View only or No access.
The same applies to setup rights. Creating, deleting and sharing dashboards, and configuring automation triggers and actions, sit with owners and administrators only. There is no way to delegate them to another role.
Step 8: Understand Folder Visibility
You do not configure folders directly. A folder hides itself when a role cannot access anything inside it, and Invisible appears next to it while you are setting permissions.
Two exceptions catch people out. A folder containing documents stays visible even when the role cannot open the tables or documents in it. A folder containing only workflows is hidden.
Step 9: Lock Down Copying and Exporting
Go to the Others tab for the two blunt instruments: Copy content and Duplicate, download or print Base. Both are ticked by default.
Note: These interact with the general permission settings the same way attachment downloads do. A custom role allowed to copy content here will still be blocked if Who can copy content is set to users with manage permission in the general panel. For non-administrators, both conditions must be satisfied.
A Sensible Order to Work In
- Create your roles before touching any settings, so you are not switching context mid-configuration.
- Set every table permission first, including the tables a role should not see at all.
- Work down through records, then fields, then views for each table that matters.
- Handle dashboards, then the Others tab last.
- Use Save and Preview rather than Save so you can check the result as that role before committing.
Practical Use Cases for SMEs and Startups
- Sales team base: Reps edit only records where they are named in the owner field, but view the whole pipeline for context.
- HR records: Salary and bank detail fields hidden from everyone outside HR, with the rest of the employee table open to managers.
- Client-facing base: An external role limited to specific views, with copying, downloading and printing all switched off.
- Finance approvals: Department heads see records matching their own cost centre and nothing else.
- Shared operations base: Contractors granted access to one table while every other folder stays invisible to them.
Frequently Asked Questions (FAQ)
Why is a permission option greyed out in Lark Base?
Almost always because the table permission above it is more restrictive. Specific permissions for records, fields and views can never exceed the table-level setting, so raise the table permission first.
Can I undo the upgrade to the new advanced permissions?
Only before you save. A Revert to Previous Version option appears in the lower-left corner of the new page, but once you click Save it disappears and the change is permanent.
How do I let someone edit only their own records?
Set the table permission to Can edit, expand Record permissions, and choose Records related to members themselves. You can then decide separately whether they see everyone else’s records or only their own.
Can I hide a single column from certain users?
Yes. Set field permissions to Custom and untick Can view all for that field. The index field and system fields such as created by and last modified date cannot be hidden.
Why can a user still not download attachments?
Three settings govern this. The attachment field must be ticked under Action permissions, Duplicate, download or print Base must be enabled on the Others tab, and the general permission settings must allow it. All three have to line up.
Can a custom role manage dashboards or automations?
No. Creating, deleting and sharing dashboards, and configuring automation, are reserved for the base owner and administrators. Other roles can be given view access to a dashboard but nothing more.
Why has a folder disappeared for one of my roles?
A folder hides automatically when the role cannot access any table or dashboard inside it. Folders containing documents stay visible regardless, while folders containing only workflows are always hidden.
Getting the Configuration Right the First Time
The panel looks dense, but the logic is consistent: table permission sets the ceiling, everything below refines within it, and a handful of settings need agreement from the general sharing panel as well. Configure one role end to end, preview it, then use it as the template for the rest.
Ready to Power Your Business with Lark?
Lark Base is just one part of an all-in-one platform that brings messaging, meetings, documents, approvals, and automations together for your entire team.
As the Platinum Partner for Lark in Malaysia, Exabytes offers tailored Lark plans, hands-on onboarding, and dedicated local support to help your team share data safely as it grows.






























