How to Configure Advanced Permissions in Lark Base

0
6

How to Configure Advanced Permissions in Lark Base

Knowing that Lark Base has advanced permissions is one thing. Sitting in front of the settings panel and working out which of the four tabs controls what is another. This is the hands-on version: every screen you will touch, in the order you will touch it, from switching the feature on to locking down exports.

Note: Only the base owner and collaborators with manage permission can turn advanced permissions on and configure them. Which Lark plan you are on determines whether view, record and field permissions can be configured at all.

Step 1: Turn On Advanced Permissions

Open the base and click the Base advanced permissions icon in the upper-right corner.

Base advanced permissions icon in the upper-right toolbar of a Lark Base

In the window that opens, click Turn On Advanced Permissions.

Turn On Advanced Permissions button on the Lark Base advanced permissions splash screen

If your base is still on the older permissions system, you will see a slightly different screen with a Try Now prompt to upgrade.

Important: While you are on the new permissions page and have not yet clicked Save, a Revert to Previous Version option sits in the lower-left corner. Once you save, that door closes and you cannot go back to the old page.

Revert to Previous Version option in the lower-left of the Lark Base advanced permissions page

Step 2: Get Your Bearings on the Permissions Page

Roles run down the left-hand side, split into System roles (Owner, Administrator, Editor, Viewer) and Custom roles you create yourself. Select a role and its permissions appear on the right, organised into four tabs: Data, Dashboard, Automation and Others.

Advanced permissions page in Lark Base with system and custom roles listed beside table permission options

At the top you will also find a switch between Grant Access Through Sharing and Only Custom Roles Can Access, which decides whether people can reach the base through a share link at all.

Step 3: Set the Table Permission First

Everything else hangs off this. On the Data tab, pick a table and choose one of four levels:

  • Can manage: Add, edit and delete every record, field and view. Because this is the ceiling, the specific permissions below are locked at their highest setting.
  • Can edit: The useful one. You can then fine-tune records, fields and views underneath.
  • View only: Read access, which you can narrow further.
  • No access: The table disappears for that role.

Tip: Specific permissions can never exceed the table permission. Set the table to View only and no amount of fiddling below will grant edit rights. If a setting appears greyed out, this is usually why.

Step 4: Configure Record Permissions

With the table set to Can edit, expand Record permissions under Specific permissions.

Record permissions in Lark Base limiting editing to records related to members themselves

First decide whether the role can add records and delete records. Then set which records they can edit and delete:

  • All records: No restriction within the table.
  • Records related to members themselves: Only records they created, or records where a person field names them.
  • Records that match specific conditions: A filter you define, such as region or status.

If you picked anything other than All records, you then set what they can see separately under Records that can be viewed. The same three options apply, plus Only editable records if you want visibility and edit rights to match exactly.

This split is the whole point of record permissions. A sales rep might edit only their own deals but still see the full pipeline, or see only their own, whichever suits the team.

Step 5: Configure Field Permissions

Still on Can edit, expand Field permissions and choose Custom. You get a grid of every field with three checkboxes each: Can view all, Can add all and Can edit all.

Field permissions table in Lark Base with view, add and edit checkboxes for each column

This is how you hide a salary column from everyone except HR while leaving the rest of the employee table open.

Two fields resist restriction. The index field is always visible, and system fields (created by, modified by, date created and last modified date) are always visible and can never be made editable, since Lark fills them in itself.

Option permissions

Scroll down within the same Custom panel to Option permissions. Here you control whether the role can add, delete or edit the choices in single-option and multiple-option fields. Only fields the role can already edit appear as selectable.

Option permissions in Lark Base showing a single option field the role cannot edit

Attachment download permissions

Below that sits Action permissions, listing every attachment field in the table. All roles can download attachments by default; deselect a field to stop them.

Action permissions in Lark Base with Can export attachments ticked for an attachment field

Important: Attachment downloads are governed by three settings at once. If Duplicate, download or print Base is unticked on the Others tab, this option cannot be selected at all. Separately, the general permission settings under Share then Permission settings control who can duplicate, print and download. A user has to clear both hurdles. And even then, they can only download from attachment fields they can see.

Step 6: Configure View Permissions

Expand View permissions to control which views a role sees and whether they can create new ones.

View permissions in Lark Base restricted to specific views, with the edit views checkbox greyed out

Choose All views or tick individual views under Specific views. Note that the two settings are mutually exclusive in one direction: pick Specific views and Can add, delete or edit views greys out.

Two behaviours worth knowing:

  • Private views ignore visibility settings entirely. They stay visible only to their owner.
  • If a role already cannot see some views, any new view is hidden from them by default. You have to grant access to each new view manually.

Step 7: Set Dashboard Visibility

Owner and Administrator always have edit permission for dashboards, and that cannot be changed. Every other role, including Editor, Viewer and any custom role, can only be set to View only or No access.

Dashboard permissions in Lark Base set to View only for a custom role

The same applies to setup rights. Creating, deleting and sharing dashboards, and configuring automation triggers and actions, sit with owners and administrators only. There is no way to delegate them to another role.

Step 8: Understand Folder Visibility

You do not configure folders directly. A folder hides itself when a role cannot access anything inside it, and Invisible appears next to it while you are setting permissions.

Tooltip in Lark Base explaining that a folder is invisible to a role due to permission settings

Two exceptions catch people out. A folder containing documents stays visible even when the role cannot open the tables or documents in it. A folder containing only workflows is hidden.

Step 9: Lock Down Copying and Exporting

Go to the Others tab for the two blunt instruments: Copy content and Duplicate, download or print Base. Both are ticked by default.

Others tab in Lark Base with Copy content and Duplicate, download or print Base ticked

Note: These interact with the general permission settings the same way attachment downloads do. A custom role allowed to copy content here will still be blocked if Who can copy content is set to users with manage permission in the general panel. For non-administrators, both conditions must be satisfied.

A Sensible Order to Work In

  1. Create your roles before touching any settings, so you are not switching context mid-configuration.
  2. Set every table permission first, including the tables a role should not see at all.
  3. Work down through records, then fields, then views for each table that matters.
  4. Handle dashboards, then the Others tab last.
  5. Use Save and Preview rather than Save so you can check the result as that role before committing.

Practical Use Cases for SMEs and Startups

  • Sales team base: Reps edit only records where they are named in the owner field, but view the whole pipeline for context.
  • HR records: Salary and bank detail fields hidden from everyone outside HR, with the rest of the employee table open to managers.
  • Client-facing base: An external role limited to specific views, with copying, downloading and printing all switched off.
  • Finance approvals: Department heads see records matching their own cost centre and nothing else.
  • Shared operations base: Contractors granted access to one table while every other folder stays invisible to them.

Frequently Asked Questions (FAQ)

Why is a permission option greyed out in Lark Base?

Almost always because the table permission above it is more restrictive. Specific permissions for records, fields and views can never exceed the table-level setting, so raise the table permission first.

Can I undo the upgrade to the new advanced permissions?

Only before you save. A Revert to Previous Version option appears in the lower-left corner of the new page, but once you click Save it disappears and the change is permanent.

How do I let someone edit only their own records?

Set the table permission to Can edit, expand Record permissions, and choose Records related to members themselves. You can then decide separately whether they see everyone else’s records or only their own.

Can I hide a single column from certain users?

Yes. Set field permissions to Custom and untick Can view all for that field. The index field and system fields such as created by and last modified date cannot be hidden.

Why can a user still not download attachments?

Three settings govern this. The attachment field must be ticked under Action permissions, Duplicate, download or print Base must be enabled on the Others tab, and the general permission settings must allow it. All three have to line up.

Can a custom role manage dashboards or automations?

No. Creating, deleting and sharing dashboards, and configuring automation, are reserved for the base owner and administrators. Other roles can be given view access to a dashboard but nothing more.

Why has a folder disappeared for one of my roles?

A folder hides automatically when the role cannot access any table or dashboard inside it. Folders containing documents stay visible regardless, while folders containing only workflows are always hidden.

Getting the Configuration Right the First Time

The panel looks dense, but the logic is consistent: table permission sets the ceiling, everything below refines within it, and a handful of settings need agreement from the general sharing panel as well. Configure one role end to end, preview it, then use it as the template for the rest.

Ready to Power Your Business with Lark?

Lark Base is just one part of an all-in-one platform that brings messaging, meetings, documents, approvals, and automations together for your entire team.

As the Platinum Partner for Lark in Malaysia, Exabytes offers tailored Lark plans, hands-on onboarding, and dedicated local support to help your team share data safely as it grows.

Explore Lark plans with Exabytes today