The invented setup
This matrix is synthetic. It describes a pretend app for a pretend business with a Notes data type holding five invented notes: three created by User A and two by User B. The intended rule, in plain words, is that a signed-in user can find and view the notes they created, and an administrator can see all of them. A logged-out visitor should find none.
If the matrix is wider than the box, scroll horizontally to read every column. Keyboard: focus the matrix and use Left/Right.
persona | before the rule | after the rule (expected)
logged-out | 5 notes found | 0 notes found
User A | 5 notes found | 3 notes found (own)
User B | 5 notes found | 2 notes found (own)
Administrator | 5 notes found | 5 notes foundWhat each row proves
The first column shows the fault: with no rule, every persona finds all five notes, including a stranger. The last column is the result the rule must give. Each count comes from a direct search for the data type, not from what a page happens to display, because a page can hide records the server has still sent.
The administrator row guards against the opposite fault. A rule that is too strict would blank the pages an administrator needs, so the test confirms their access survives.
- Count records by a search, not by eye on a page.
- Test the logged-out persona first.
- Include a persona that should keep full access.
Pages and the checker
After the counts pass, every page that uses Notes is opened as each persona. A page that depended on a field a persona can no longer view may show an empty state, and that is repaired as part of the work. Finally the privacy rules checker is run; it flags fields anyone can access, needs sample data and reports without changing anything, so any field it lists is either intended to be public or is tightened.
- Open each page as each persona.
- Run the checker after the change, not before.
- Keep the matrix with the dated results.
What this does not prove, and a priced route
It does not prove the whole app is secure, only that this data type behaves for these personas on this development version. It says nothing about past exposure and is not a certification. The fixed-scope fix of one data type is priced at £325 as an untested proposal and paid only after you sign off. Send the data type's name, who should see what in words, and screenshots with names removed, never logins or real records. This matrix illustrates a method; it is not a delivery for any client.
Sources and limits
- Bubble manual: protecting data with privacy rules Checked 2026-10-11.
- Privacy rules combine attributes of the thing with attributes of the current user, and access is the sum of the rules a user matches.
- Bubble manual: privacy rules checker Checked 2026-10-11.
- The checker flags fields that can be accessed with no restrictions and needs sample data.