Skip to main content

Understanding change propagation

Understand why access changes can take a short period before they take effect for users, groups, and service accounts.

When to use this​

  • Use it after creating, editing, or removing data rules.
  • Use it after changing group membership or roles.
  • Use it when a user still sees the old access right after a change.

Before you start​

  • Confirm the change was saved successfully.
  • Note the time of the change.
  • Identify who or which account was affected.

Step by step​

  1. After saving the change, mention that propagation may take a moment.
  2. Ask the user to wait a little.
  3. Tell them to refresh the screen or open a new session.
  4. Test again with a simple query.
  5. If the behavior persists, review the rule, the group, and the role.
  6. Use the audit trail to confirm the action was saved.

What happens next​

  • Effective access reflects the change.
  • Users may see data that was granted, or lose access that was removed.
  • The change is recorded for future investigation.

Common errors​

  • Concluding the rule failed without waiting for propagation.
  • Forgetting that groups also influence access.
  • Testing with a different user than the one affected.

Good practice​

  • Set expectations about propagation on sensitive changes.
  • Record the time of the change in tickets.
  • Use a simple query to validate the effect.

Next steps​