You have locked down a base with advanced permissions, then attached a form to it.
What can someone actually see when they fill that form in?
The answer depends on how they opened it, and it is not always what you would expect. L
ink fields behave one way inside the base and another through a share link, while formula and lookup fields ignore your permission settings entirely.
The Two Ways to Fill In a Form
Method 1: From the form view inside the base
Open the base, click the form view, then click Fill at the top of the page.
For this route, anyone with an advanced permissions role needs view permission for both the form view and the table it belongs to.
Method 2: Through a shareable link
Open the form in a browser using the link the form administrator shares.
Here the respondent needs no view permission for the underlying table at all. The administrator controls who can reach it using the shareable scope in the share settings panel.
Note: This distinction is the root of almost every surprise below. The same form, filled two different ways, exposes different amounts of data.
What Respondents See in Link Fields
One-way and two-way link fields are where the two methods diverge most sharply.
Filling from the form view
Respondents can only see and select records they have view permission for. For those records, they see the index field and the other fields, which gives them useful context when choosing.
This suits situations where the extra context matters and the audience is internal. A sales representative linking an order to a customer sees only the customers they are responsible for, along with the detail they need to pick the right one.
Filling through a shareable link
Respondents see and can select every record in the index field of the linked table, but nothing else. No other columns are exposed.
Important: Record-level permissions do not apply on this route. Even records a person has no view permission for will show their index field value in the dropdown. Bear that in mind if your index field contains anything you would not want a respondent to read, such as client names or deal references.
The upside is that the rest of the table stays hidden. When employees request office supplies, they see the item names they need to choose from but not the stock levels or costs sitting alongside.
Formula and Lookup Fields Ignore Permissions
If a form contains formula or lookup fields, respondents see the calculated output or the looked-up result no matter how they opened the form and regardless of whether they can view the referenced data source.
This is usually a feature rather than a problem. Someone filling in an order can see the quoted price generated by a formula even though they have no access to the unit price and quantity fields in the product table that produced it.
Important: The flip side is that a formula can leak what its inputs imply. If a lookup or formula field would reveal something sensitive, restricting the source table will not help. Remove the field from the form instead.
Referenced Option Fields Are Always Visible
Single option and multiple options fields whose choices are pulled from another table behave the same way. Respondents can view and select all the options whatever their permission on the source table and however they reached the form.
Choosing the Right Method
| If you need respondents to… | Use |
|---|---|
| See only the records that belong to them | Form view, with record permissions configured |
| Pick from a list without seeing any surrounding data | Shareable link |
| Submit without any access to the base | Shareable link |
| See supporting columns while choosing a record | Form view |
| Submit from outside your organisation | Shareable link, with the scope set accordingly |
Practical Use Cases for SMEs and Startups
- Sales order entry: Reps fill from the form view so they see only their own accounts in the customer link field.
- Office supply requests: Staff use a share link so they pick item names without seeing stock or cost.
- Client intake forms: External contacts submit through a link with no access to the base behind it.
- Internal quoting: A formula field shows the calculated price while the underlying cost fields stay restricted.
- Event or training sign-ups: A share link keeps the attendee list itself private while still letting people register.
Frequently Asked Questions (FAQ)
Do respondents need access to the base to fill in a Lark Base form?
Not if you share a link. They only need view permission for the form view and its table when filling from the form view inside the base.
Why can a respondent see records I restricted with advanced permissions?
They are almost certainly using a shareable link. On that route, the index field of every record in a linked table is visible and selectable, regardless of record-level permissions.
Why does a form show fewer records for one person than another?
Record permissions apply when filling from the form view, so each person sees only the linked records their role allows. The same form opened through a share link shows everyone the full index field.
Can I hide a formula result from form respondents?
Not through permissions. Formula and lookup fields display their output to anyone filling the form, so the only reliable way to hide one is to remove the field from the form.
Do respondents see all the options in a linked option field?
Yes. Single option and multiple options fields that reference another table show every option to every respondent, whatever their permissions and however they opened the form.
How do I control who can open a shared form?
Use the shareable scope in the share settings panel. The form administrator sets whether the link works for anyone or only for people inside the organisation.
Matching the Method to the Audience
Advanced permissions do a thorough job inside the base, but a form is a doorway with its own rules. Before you publish one, ask who will be filling it in and by which route, then check what the link fields will reveal on that route. For anything sensitive, the safest test is to open the form the way your respondents will and look at it with their eyes.
Ready to Power Your Business with Lark?
Lark Base is just one part of an all-in-one platform that brings messaging, meetings, documents, approvals, and automations together for your entire team.
As the Platinum Partner for Lark in Malaysia, Exabytes offers tailored Lark plans, hands-on onboarding, and dedicated local support to help your team collect data without exposing more than intended.























