Property-based access control

Property-based access control grants or denies permission to read or traverse nodes or relationships based on property/value conditions. Each property-based privilege can only be restricted by a single property. For information about the syntax of these privileges, see Read privileges.

When using property-based access control, ensure the property used for the rule cannot be modified. Users who can change this property can affect the granted property-based privileges.

Exercise caution when using DENY for property-based access control. A DENY rule fails open when its criteria cannot be evaluated, which means the restriction is not applied and access is granted by default if a broader GRANT exists. For details, see Limitations → Fail-open DENY behavior.

Sharded property databases do not support property-based access control.

Syntax

To specify the property/value conditions of the privilege, you can use the following syntax:

{GRANT | DENY | REVOKE [GRANT | DENY]}
[IMMUTABLE]
{MATCH | READ | TRAVERSE}
  ON { HOME GRAPH | GRAPH[S] { * | name[, ...] } }
    [
      ELEMENT[S] { * | label-or-rel-type[, ...] }
      | NODE[S] { * | label[, ...] }
      | RELATIONSHIP[S] { * | rel-type[, ...] }
      | FOR {
          ([var][:label["|" ...]] "{" property: value "}")
          | (var[:label["|" ...]])
            WHERE [NOT] { var.property { = | <> | > | >= | < | <= } value | value { = | <> | > | >= | < | <= } var.property | var.property { IS NULL | IS NOT NULL } | var.property IN { "["[value[, ...]]"]" | listParam } | value IN var.property }
          | (var[:label["|" ...]]
            WHERE [NOT] { var.property { = | <> | > | >= | < | <= } value | value { = | <> | > | >= | < | <= } var.property | var.property { IS NULL | IS NOT NULL } | var.property IN { "["[value[, ...]]"]" | listParam } | value IN var.property } )
          | ()[<]-"["[var][:type["|" ...]] "{" property: value "}" "]"-[>]()
          | ()[<]-"["var[:type["|" ...]]"]"-[>]()
            WHERE [NOT] { var.property { = | <> | > | >= | < | <= } value | value { = | <> | > | >= | < | <= } var.property | var.property { IS NULL | IS NOT NULL } | var.property IN { "["[value[, ...]]"]" | listParam } | value IN var.property }
          | ()[<]-"["var[:type["|" ...]]
            WHERE [NOT] { var.property { = | <> | > | >= | < | <= } value | value { = | <> | > | >= | < | <= } var.property | var.property { IS NULL | IS NOT NULL } | var.property IN { "["[value[, ...]]"]" | listParam } | value IN var.property } "]"-[>]()
      }
    ]
 {TO | FROM} role[, ...]

The following forms are available from Cypher 25 (introduced in Neo4j 2026.08):

In Cypher 5, the property must appear on the left-hand side of a scalar comparison operator, and IN can only be used to check the property against a list of values (var.property IN [value, …​]).

Performance considerations

Adding property-based access control may lead to a significant performance overhead in certain scenarios. See Limitations for more detailed information.

When having property rules, the following factors can worsen the impact on performance:

  • The number of properties on the nodes and relationships concerned (more properties = greater performance impact).

  • The number of property-based privileges (more property-based privileges = greater performance impact).

  • The type of the privilege: TRAVERSE property-based privileges have greater performance impact than READ property-based privileges.

  • The type of storage medium in operation. The impact of the property-based privileges on performance is considerably amplified by accessing disc storage.

To reduce the performance impact, it is recommended to use the block storage format as it is better optimized for the kind of read required for the resolution of property-based privileges.

For performance-critical scenarios, it is recommended to design privileges based on labels.

Examples

You can use the following syntax for defining a property-based privilege:

GRANT privilege-name ON GRAPH graph-name FOR pattern TO role-name

The user role does not need to have READ privilege for the property used by the property-based privilege.

Grant a property-based privilege on a specific property using the value of another property

The following example shows how to grant permission to READ the address property on Email or Website nodes with domain exampledomain.com to role regularUsers:

GRANT READ { address } ON GRAPH * FOR (n:Email|Website) WHERE n.domain = 'exampledomain.com' TO regularUsers

Alternatively, you can use the following syntax:

GRANT READ { address } ON GRAPH * FOR (:Email|Website {domain: 'exampledomain.com'}) TO regularUsers

The following example shows how to grant permission to READ the since property on OWNS relationships having classification equal to UNCLASSIFIED to role regularUsers:

GRANT READ { since } ON GRAPH * FOR ()-[o:OWNS]-() WHERE o.classification = 'UNCLASSIFIED' TO regularUsers

Grant a property-based privilege with the property on either side of the operator

The property can appear on either side of a scalar comparison operator (=, <>, >, >=, <, ). The following example shows how to grant permission to READ all properties on nodes where the value 3 is less than the securityLevel property to the role regularUsers:

GRANT READ {*} ON GRAPH * FOR (n) WHERE 3 < n.securityLevel TO regularUsers

Placing the property on the right is equivalent to the property-on-the-left form n.securityLevel > 3. When the property is on the right, the operator is mirrored, so this rule matches nodes whose securityLevel is greater than 3. Regardless of the orientation used to create the privilege, it is always stored and listed in the canonical property-on-the-left form. Running SHOW PRIVILEGES AS COMMANDS for the example above returns the rule as n.securityLevel > 3.

Grant a property-based privilege using NULL

The following example shows how to grant permission to TRAVERSE nodes with the label Email where property classification is NULL to role regularUsers:

GRANT TRAVERSE ON GRAPH * FOR (n:Email) WHERE n.classification IS NULL TO regularUsers

Deny a property-based privilege using a comparison operator

The following example shows how to deny permission to READ and TRAVERSE nodes and relationships where the property classification is different from UNCLASSIFIED to role regularUsers:

DENY MATCH {*} ON GRAPH * FOR (n) WHERE n.classification <> 'UNCLASSIFIED' TO regularUsers
DENY MATCH {*} ON GRAPH * FOR ()-[r]-() WHERE r.classification <> 'UNCLASSIFIED' TO regularUsers

These DENY rules fail open for nodes and relationships without a classification property. When the property is missing, the <> comparison cannot be evaluated, so the restriction is not applied and access is granted by default if a broader GRANT exists. For details, see Limitations → Fail-open DENY behavior.

Grant a property-based privilege on all properties using a property value

The following example shows how to grant permission to READ all properties on nodes and relationships where the property securityLevel is higher than 3 to role regularUsers:

GRANT READ {*} ON GRAPH * FOR (n) WHERE n.securityLevel > 3 TO regularUsers
GRANT READ {*} ON GRAPH * FOR ()-[r]-() WHERE r.securityLevel > 3 TO regularUsers

The role regularUsers does not need to have READ privilege for the property securityLevel used by the property-based privilege.

Grant a property-based privilege using a list of values

The following example shows how to grant permission to READ all properties on nodes and relationships where the property classification is included in the list [UNCLASSIFIED, PUBLIC]:

GRANT READ {*} ON GRAPH * FOR (n) WHERE n.classification IN ['UNCLASSIFIED', 'PUBLIC'] TO regularUsers
GRANT READ {*} ON GRAPH * FOR ()-[r]-() WHERE r.classification IN ['UNCLASSIFIED', 'PUBLIC'] TO regularUsers

Grant a property-based privilege based on a value in a list property

You can check whether a value is a member of a list-valued property using the value IN var.property syntax. Here, the property stored on the node or relationship is a list, and the rule matches when the given value is an element of that list. This is different from var.property IN [value, …​], which checks whether a single-valued property matches one of the values in a given list.

The following example shows how to grant permission to READ all properties on nodes where the list-valued regions property contains the value 'EU' to the role regularUsers:

GRANT READ {*} ON GRAPH * FOR (n) WHERE 'EU' IN n.regions TO regularUsers

The value on the left of IN must be a single value that is not NULL or NaN. The rule only matches when the property is a list that contains the value. If the property is missing or is a single (scalar) value rather than a list, the rule does not match.

You can also negate the condition to match nodes and relationships whose list property does not contain the value. The following example shows how to grant permission to READ and TRAVERSE nodes and relationships where the regions property does not contain the value 'EU' to the role regularUsers:

GRANT MATCH {*} ON GRAPH * FOR (n) WHERE NOT 'EU' IN n.regions TO regularUsers
GRANT MATCH {*} ON GRAPH * FOR ()-[r]-() WHERE NOT 'EU' IN r.regions TO regularUsers

The value on the left of NOT IN must be a single value that is not NULL or NaN. The rule only matches when the property is a list that does not contain the value. If the property is missing or is a single (scalar) value rather than a list, the rule does not match.

Grant a property-based privilege using temporal value

The following example shows how to grant permission to READ all properties on nodes and relationships where the property createdAt is later than the current date:

GRANT READ {*} ON GRAPH * FOR (n) WHERE n.createdAt > date() TO regularUsers
GRANT READ {*} ON GRAPH * FOR ()-[r]-() WHERE r.createdAt > date() TO regularUsers

The date() function is evaluated, and the value used to evaluate the privilege is the date when the property-based privilege is created. Keep this in mind when designing your property rules, and use the SHOW PRIVILEGES AS COMMANDS command to check the stored value. This is essential when revoking property-based privileges containing evaluated function values like date().

Not all temporal values are comparable, see Cypher Manual → Equality, ordering, and comparison of value types.

You can show the privilege created by the command in the previous example as a revoke command by running:

SHOW ROLE regularUsers PRIVILEGES AS REVOKE COMMANDS
Table 1. Result
command

REVOKE GRANT READ {*} ON GRAPH * FOR (n) WHERE n.createdAt  date('2024-10-25') FROM `regularUsers`

REVOKE GRANT READ {*} ON GRAPH * FOR ()-[r]-() WHERE r.createdAt  date('2024-10-25') FROM `regularUsers`

Rows: 2

Glossary

allocator

A component in the cluster that allocates databases to servers according to the topology constraints specified and an allocation strategy.

asynchronous replication

Asynchronous replication is used by secondary copies to poll for new transactions, which means they cannot be guaranteed to have received the most recent transactions. This enables efficient scale-out of read-performance.

Aura instance

A fully-managed DBMS represented by a single instance ID, that is running in the Neo4j Aura cloud.

auto-commit transaction

An automatically committed transaction that contains a single query.

Bolt protocol

Bolt is a protocol used for interaction between Neo4j instances and drivers.

bookmark

A marker the client can request from the cluster to ensure that it is able to read its own writes so that the application’s state is consistent and only databases that have a copy of the bookmark are permitted to respond.

category (Bloom)

A category is based on a node label and is defined in a Perspective as a way of visually distinguishing nodes with the same label(s).

causal consistency

All servers in a cluster agree on the order in which transactions take place. The position of a server on the causal chain can be guaranteed using a bookmark.

cluster

A Neo4j DBMS that spans multiple servers working together to increase fault tolerance and/or read scalability. Databases on a cluster may be configured to replicate across servers in the cluster thus achieving read scalability or high availability.

client application

Software that interacts with a Neo4j server.

commit

A commit is the successful completion of a transaction, which ensures durability of any changes made. For more details, visit Operations Manual → Transaction management.

composite database

Composite databases are the means to access partitioned graph data with a single Cypher query.

constraint

Constraints are sets of data modeling rules that ensure the data is consistent and reliable.

Cypher®

Neo4j’s graph query language.

data model

A data model defines how information is organized in a database. A good data model will make querying and understanding your data easier. In Neo4j, the data models have a graph structure.

database

A database is a container used by the DBMS to manage and store graph data. The physical structure of data is controlled by the database.

database vs graph

Databases are the physical containers of graph data. Graphs are the logical structure of data in Neo4j.

Database Management System

Database Management System, or DBMS, capable of managing multiple databases. A DBMS may run on a single server, or span several servers configured as a cluster.

database schema

The prescribed property existence and datatypes for nodes and relationships.

deallocate

An act of removing a database from a server or a server from a cluster without loss of data or reduced fault tolerance.

degree (of a node)

The number of relationships of a specific node; loops are counted twice.

disaster recovery

A manual intervention to restore availability of a cluster, or databases within a cluster.

driver

A software library that provides access to Neo4j from a particular programming language.

election

In the event that the Raft leader becomes unresponsive, followers automatically trigger an election and vote for a new leader.

entity

A node or a relationship.

expression (Cypher)

A component of a Cypher query which produces values. It may be used in projections, as a predicate, or when setting properties on graph elements.

fabric

Fabric is the architectural design of a unified system that provides a single access point to local or distributed graph data.

fault tolerance

A guarantee that a cluster can maintain a database’s persistence and availability in the event of one or more servers failing.

follower

A primary copy of a database acting as a follower, receives and acknowledges synchronous writes from the leader.

Generative AI (GenAI)

A type of artificial intelligence (AI) system that generates text, images, or other media in response to prompts.

graph

A logical representation of a set of nodes where some pairs are connected by relationships.

index

Data structure that improves read performance of a database.

knowledge graph

A specific type of graph that has an organizing principle so that a user (or a computer system) can reason about the underlying data. The organizing principle provides an additional layer of structure that adds context to support knowledge discovery.

label

Marks a node as a member of a named and indexed subset. A node may be assigned zero or more labels.

leader

A single primary copy of a database is designated as the leader. It receives all write transactions from clients and replicates writes synchronously to followers and asynchronously to secondary copies of the database.

main database

In terms of Neo4j Enterprise Studio, the database(s) containing the user’s data. Can exist in the same Neo4j deployment as the tool asset database.

motif

A description of a specific pattern within a graph.

node

A node represents an entity or discrete object in your graph data model. Nodes can be connected by relationships, hold data in properties, and are classified by labels.

operator

A symbol representing a mathematical or logical operation.

parameter

Named value provided when running a Cypher statement.

path

A sequence of nodes and the relationships connecting them, that does not contain duplicate relationships. Several paths can match a pattern.

pattern

A specific arrangement of nodes and relationships that can be matched in a graph. A pattern follows a motif.

perspective (Bloom)

A Perspective defines a certain business view or domain that can be found in the target Neo4j graph. A single Neo4j graph can be viewed through different Perspectives, each tailored for a different business purpose.

primary

A copy of the database that is able to process write transactions and is eligible to be elected as a leader. It participates in fault tolerant writes as it is part of the majority required to acknowledge and commit write transactions.

primary vs secondary

In a cluster, databases can operate in either primary or secondary mode. Primary databases are able to process write and read transactions, ensuring fault tolerance. Secondary databases are replicated asynchronously from primaries, and their main purpose is to provide read scaling within the cluster.

project (Aura)

An isolated environment in the unified Aura console that contains its own database instances, configurations, and resources. Preceded by tenant in the classic Aura console.

property

Properties are key-value pairs that are used for storing data on nodes and relationships.

query (Cypher)

A statement that retrieves or writes information to a database.

Raft group

A group of servers that are participating in hosting a particular database in primary mode.

Raft group member

A server that is participating in a Raft group. A server can be a member of one or more groups.

Raft log

A shared log between all Raft group members that is guaranteed to be consistently updated and viewed by those members. The log contains both database data and operational state of the Raft group.

Raft protocol

The networking mechanism that enables a database to replicate its data across multiple servers to give high availability for accessing the data and high durability to the data stored.

read scaling

Distributing query load by creating additional database copies hosted in secondary mode (read-only).

relationship

A relationship represents a connection between nodes in your graph data model. Relationships connect a source node to a target node, hold data in properties, and are classified by type.

secondary

An asynchronously replicated copy of the database that provides read scaling within the cluster.

seed

A seed is a database dump or a full backup used to create a database on a cluster. This is sometimes called seeding.

server

A physical machine, a virtual machine, or a container running an instance of Neo4j. Servers can be standalone or part of a cluster.

session

A causally linked sequence of transactions.

session consistency

An alternative name for Neo4j’s causal consistency.

standalone

A single server running Neo4j and not part of a cluster.

synchronous replication

Synchronous replication requires the leader primary to replicate a transaction and block the commit until a quorum of the follower primaries acknowledges that the transaction is successfully replicated. Once the transaction is replicated, the commit is allowed to proceed. This ensures data durability and consistency within the cluster.

system database

A database used by Neo4j to store system information.

tenant (Aura)

An isolated environment in the classic Aura console that contains its own database instances, configurations, and resources. Replaced by project in the unified Aura console.

tool asset database

In terms of Neo4j Enterprise Studio, the database where tools' assets are stored. This can be in the same Neo4j deployment as the main database(s) or in a separate deployment.

topology

A configuration that describes how the copies of a database should be spread across the servers in a cluster, see primary mode and secondary mode.

transaction

A transaction comprises a unit of work performed against a database. It is treated in a coherent and reliable way, independent of other transactions. Transactions comply with the ACID consistency model (atomic, consistent, isolated, and durable).