You can control access to records based on a value in a field. For example, for compliance with the General Data Protection Regulation (GDPR), you want only the EU data stewards to access records that have an address within the European Union.
You can create field filters on business entities. In a field filter, you define access permissions in terms of deny rules, allow rules, or a mix of both types of rules. A rule is made up of a value for the field and the applicable user roles. For example, you might create a field filter on a GDPR field. Create an allow rule on the field with the value of true and select the DataSteward-EU role. Use the Remaining Values rule to assign false to all other user roles.
The field filters on a business entity override the field filters on a reference entity. A user role might be allowed to see a subset of lookup values based on the field filter in the reference entity, but if a field filter on the business entity denies access to some of those values, the user role cannot see the records with those values.