- Do not store Personal Identifiable Information in tuples
- Always specify authorization model ID whenever possible
Do Not Store Personal Identifiable Information in Tuples
You can use any string for user and object identifiers, however you should not input or assign identifiers that include Personal Data or any other sensitive data, such as data that may be restricted under regulatory requirements.Always specify authorization model ID whenever possible
It is strongly recommended that authorization model ID be specified in your Relationship Queries (such as Check and ListObjects) and Relationship Commands (such as Write). Specifying authorization model ID in API calls have the following advantages:- Better performance as OpenFGA will not need to perform a database query to get the latest authorization model ID.
- Allows consistent behavior in your production system until you are ready to switch to the new model.
Related Sections
Check the following sections for more on recommendation for managing relations and model in production environment.Migrating Relations
Learn how to migrate relations in a production environment