Vladi Gubler
Vladi Gubler
October 08, 2025
Stay in the know
Get helpful videos

Introduction

In sophisticated business apps, it's often necessary to enforce permissions dynamically based on relationships in your data. One useful pattern is to use lookup columns to drive permissions. Rather than hard-coding specific user accounts or roles, you can leverage a lookup to link to another centralized list that assigns authority, and then enforce access based on that value. Using Infowise Ultimate Forms, you can leverage this approach in form permission rules or even alert recipients.

This approach minimizes duplication, improves flexibility, and simplifies administration.


Scenario: Departmental Vacation Requests

Let’s illustrate with a typical scenario.

You have:

  • A Departments list, which includes a column called Manager (Person or Group) that designates who is the manager for each department.
    Departments

  • A Vacation Requests list, where users submit requests including columns such as:

    1. Requester (who is requesting the time off)

    2. Start Date / End Date

    3. Department (a lookup to the Departments list)

    4. Approval columns (e.g. Status, Comments)
      Vacation Requests form

The business requirement: Once a vacation request is submitted, the department’s manager should be able to approve it, but only for the requests tied to their department. Other managers or users shouldn’t be able to edit the approval columns outside of their authority.

Instead of writing complex code or per-item permissions manually, you can do the following:

  1. In the Departments list, include a Person/Group column (say, “Manager”) and fill it so each department points to its manager.

  2. In your Vacation Requests form, set up a Write permission rule targeting the Approval columns or the “Approval” tab in your form.

  3. Because Department is a lookup column, you can reference the Manager sub-column from that lookup as the controlling user identity.

That is: when defining the permission rule, specify that only the Manager obtained via the lookup (i.e., the Manager column within the linked Departments record) can edit the Approval area. The form engine of Ultimate Forms exposes the lookup’s target-person column automatically in the permission rules builder.

As a result:

  • If you open a vacation request for a department you manage, you can edit the approval columns (e.g. set “Approved” or “Rejected”).

  • If you open a vacation request for a department you do not manage, those approval columns or tabs will be hidden or read-only.

This gives you dynamic, column-level permission control without complex workflows or scripts.


Why This Is Powerful & Useful

Here are several advantages and use-cases of applying permissions via lookup:

  • Centralized Role Maintenance: If a department’s manager changes, you only need to update one list (the Departments list). All related permissions will automatically follow.

  • Scalability: You don’t have to manually apply item-level permissions across hundreds or thousands of vacation request items. The permission logic is baked into the form rules.

  • Reduced Errors: Since you’re not managing per-request security settings manually, you minimize human error in permissions.

  • Dynamic Authorization: You can apply similar patterns elsewhere—for example:

    • Project → Project Lead → Only the project lead can approve tasks

    • Client Account → Account Owner → Only the account owner can close or delete the record

    • Cost Center → Financial Manager → Only the manager can edit budget overrides


Step-by-Step Guide (Expanded)

Below is a more detailed walkthrough:

Step Action Purpose / Notes
1 Add a Person/Group column (“Manager”) in source list (Departments) This column holds each department’s manager
2 Populate the Manager column for all departments Ensures that lookup targets exist
3 In Vacation Requests list/form, have a Department lookup pointing to Departments This establishes the link that permission logic will use
4 Enable a Write Permission Rule on the Approval section/tab in the form This is the area you want restricted
5 In the permission rule’s settings, select "User in column". Select the lookup column (Department) and then the lookup’s Manager column This makes only the referenced manager have edit rights
6 Test the form under different user accounts: one manager of a department, another manager for a different department, a non-manager user Validate that only the correct manager can approve

Considerations, Caveats & Best Practices

  • Performance: If your lists are very large, lookup operations and permission evaluation may add complexity or slight latency. Always test with realistic data volumes.

  • Cascading Security: This approach controls form-level editing permission. If other access paths exist (e.g. via raw list view, API, or other tools), you must ensure they respect the same security logic or disable them.

  • Access via Other Interfaces: If users access items via the SharePoint list view, or via APIs, be sure to lock down those surfaces or apply equivalent permission controls.

  • Changing Managers: If a department’s manager changes mid-cycle, old and new approval rights shift automatically. Make sure users understand that past approvals cannot be altered unless allowed.

  • Fallback / Exception Handling: What if the Manager column is blank or misconfigured? You may want a fallback permission (e.g., site admins always have edit rights) to avoid orphaned items.

  • Complex Scenarios: You can extend this to multi-level lookups or chained permissions (e.g. Department → Division → Division Manager), but you need to carefully design lookups and permission priority rules.


Example: Visual Flow (Hypothetical Screenshots)

  1. Departments list:

Department ID Department Name Manager (Person)
D001 Sales Jane Doe
D002 HR John Smith
  1. Vacation Requests form:

  • Columns: Requester, Start Date, End Date, Department (lookup to Departments)

  • Approval Tab: Status, Comments, Approver Signature

  1. Permission Rule Setup:

  • Target: Approval Tab or columns - select the relevant tab, container or column to apply permission.

  • Write - set the permission level.
  • For users/groups in column [Department][Manager]

  • Add another, Read permission without specifying the user for read-only cases.
    Permission rule

Result:

  • Jane Doe opens a request for Sales → can edit Approval.

  • Jane Doe opens a request for HR → read-only on Approval.

  • John Smith opens HR → can edit Approval.

  • Regular user opens any request → cannot edit the Approval part.

Summary

Using lookup-based permissions in SharePoint with Infowise Ultimate Forms gives organizations a smarter, more automated way to control access to forms and data. It eliminates repetitive manual configuration, ensures data integrity, and provides a clear audit trail of responsibility. Whether you’re managing vacation approvals, project ownership, or client accounts, this approach keeps your workflows secure, adaptable, and easy to maintain. And all within SharePoint and without a single line of code.

Loading...

Add your comment

Comments are not meant for support. If you experiencing an issue, please open a support request.
Products
In this post I'm going to go over the Signature component of our Ultimate Forms. I will explain how it can help your SharePoint system meet federal regulations, like FDA 21 CFR Part 11.SharePoint is a great tool for managing all kinds of data: documents, business processes, you name it. Coupled with a Single Sign-on, entering data is a breeze,...
Products
When we started to develop Ultimate Forms, we did not position it to be an InfoPath competitor or replacement. We aimed to create a platform that helps our customers use SharePoint better. We wanted to close the gap between their needs and what SharePoint can do. This way, they wouldn't have to spend money on expensive custom development. We did...
Products
Vladi Gubler | April 30, 2025
If you’ve ever used Survey lists in SharePoint, you’re likely familiar with a powerful and often underappreciated feature: the Rating Scale column. This special column type presents a matrix of statements or questions alongside a numeric scale, typically used for gathering structured feedback. The idea is simple but incredibly effective - allow...
Build powerful business applications in SharePoint using only your browser.
100% No-Code Solution
It’s never been easier to create, innovate, and share. All you need is your web browser!
Cost-Effective
Address business process pain points immediately. Save time and money.
Fantastic Support Team
In addition to our responsive support team, a wide variety of resources, documentations, tutorials, blogs and webinars is available to you
Microsoft partner logo
© 2005-2025 Infowise Solutions Ltd. All rights reserved.
Privacy | Cookie Policy | Accessibility | Cloud SLA