# Comment tagging should respect user table permissions

**URL:** <https://community.noloco.io/t/comment-tagging-should-respect-user-table-permissions/259>\
**Category:** Feature Requests\
**Tags:** feature-request\
**Created:** [February 12, 2024, 3:47pm UTC](https://community.noloco.io/t/comment-tagging-should-respect-user-table-permissions/259 "2024-02-12T15:47:51Z")\
**Posts on this page:** 19\
**Page:** 1

<div class="post-metadata">

**Author:** ![buildwithjoel](https://dub1.discourse-cdn.com/flex005/user_avatar/community.noloco.io/buildwithjoel/32/1537_2.png) [@buildwithjoel](https://community.noloco.io/u/buildwithjoel)\
**Post date:** [February 12, 2024, 3:47pm UTC](https://community.noloco.io/t/comment-tagging-should-respect-user-table-permissions/259/1 "2024-02-12T15:47:51Z")

</div>

**Feature Request**

- For in-comment tags to respect user table permissions.
- For example, when a client logs into a portal and adds a @tag, it should only display the user names of the users they’re allowed to see, according to any permissions configured on the user table.

---

<div class="post-metadata">

**Author:** ![onlymatt](https://avatars.discourse-cdn.com/v4/letter/o/48db29/32.png) [@onlymatt](https://community.noloco.io/u/onlymatt)\
**Post date:** [July 18, 2024, 7:49pm UTC](https://community.noloco.io/t/comment-tagging-should-respect-user-table-permissions/259/2 "2024-07-18T19:49:40Z")

</div>

Hoping to bring this back to attention. This is one of the few hard limitations that is keeping me from using noloco with additional user groups. For now we have many employees with different permissions using our app and its very possible and easy to tag someone in an area that they cannot access. I want to bring our clients into the app but at present they would be allowed to tag any of my team, most of whom never have direct contact with the client. It’s a recipe for confusion all around so my company continues to use other services such as Basecamp for our clients.

---

<div class="post-metadata">

**Author:** ![carlos](https://avatars.discourse-cdn.com/v4/letter/c/ecae2f/32.png) [@carlos](https://community.noloco.io/u/carlos)\
**Post date:** [July 18, 2024, 11:11pm UTC](https://community.noloco.io/t/comment-tagging-should-respect-user-table-permissions/259/3 "2024-07-18T23:11:52Z")

</div>

Hey @onlymatt, you can limit mentions to users in the same role/group in the Noloco user table by creating a permission for that role/group so they can only see each other. You would have to create a permission for each user group though. It’s not exactly what you and @buildwithjoel are requesting but you can use this workaround in the meantime. Hope this helps to encourage you to use the comments/mentions feature within your company.

 ![mentions permissions](https://europe1.discourse-cdn.com/flex005/uploads/noloco/original/1X/a08fe877b61ac7e3f5cf0937f63669e16fca5ee3.png)

---

<div class="post-metadata">

**Author:** ![darragh](https://dub1.discourse-cdn.com/flex005/user_avatar/community.noloco.io/darragh/32/12_2.png) [@darragh](https://community.noloco.io/u/darragh)\
**Post date:** [July 19, 2024, 7:27am UTC](https://community.noloco.io/t/comment-tagging-should-respect-user-table-permissions/259/4 "2024-07-19T07:27:56Z")

</div>

> [@onlymatt](#):
>
> most of whom never have direct contact with the client. It’s a recipe for confusion all around so my company continues to use other services such as Basecamp for our clients.

It would be great to hear your **ideal** solution @onlymatt

As we mention above, we do give you control over who can get tagged, but adding the different dimension of _context_ would make that configuration much more complicated, so it would be great to hear what you would need

---

<div class="post-metadata">

**Author:** ![onlymatt](https://avatars.discourse-cdn.com/v4/letter/o/48db29/32.png) [@onlymatt](https://community.noloco.io/u/onlymatt)\
**Post date:** [July 19, 2024, 12:33pm UTC](https://community.noloco.io/t/comment-tagging-should-respect-user-table-permissions/259/5 "2024-07-19T12:33:44Z")

</div>

@carlos solution does actually solve the large issue of being able to involve my clients in our app so that’s much appreciated. I can keep the client permission from tagging the field employee or warehouse permission so that’ great.

Other than that it comes down to how our information is partitioned among my team. I have many contexts where for example field employees and directors need to be able to tag eachother and just as many where they don’t because field employees don’t have access to the page. Setting the permissions at the user level is ineffective here. But, since they are all my employees or team members I don’t consider it a large issue, more of an aesthetic or incidental issue if a director were to unwittingly tag a field employee on a page that they can’t access.

---

<div class="post-metadata">

**Author:** ![darragh](https://dub1.discourse-cdn.com/flex005/user_avatar/community.noloco.io/darragh/32/12_2.png) [@darragh](https://community.noloco.io/u/darragh)\
**Post date:** [July 19, 2024, 1:37pm UTC](https://community.noloco.io/t/comment-tagging-should-respect-user-table-permissions/259/6 "2024-07-19T13:37:43Z")

</div>

That’s great @onlymatt - happy to hear we have a solution for you.

We’re definitely interested in coming up with something more versatile for comment mentions specifically

It could be different filters for comments on different tables, but it gets complicated to setup and maintain

---

<div class="post-metadata">

**Author:** ![onlymatt](https://avatars.discourse-cdn.com/v4/letter/o/48db29/32.png) [@onlymatt](https://community.noloco.io/u/onlymatt)\
**Post date:** [July 19, 2024, 2:42pm UTC](https://community.noloco.io/t/comment-tagging-should-respect-user-table-permissions/259/7 "2024-07-19T14:42:31Z")

</div>

@darragh given that there is the work around provided I would say my needs are largely met. The ideal solution would be tagging is only available to those who can view the page automatically. If that weren’t possible to do then I’d favor the current set up over having to manually set comment tagging permissions throughout. Basecamp is essentially set up that way now, where you have to manually select which users will be on a project when it is setup and its not an ideal level of maintenance for my team.

---

<div class="post-metadata">

**Author:** ![buildwithjoel](https://dub1.discourse-cdn.com/flex005/user_avatar/community.noloco.io/buildwithjoel/32/1537_2.png) [@buildwithjoel](https://community.noloco.io/u/buildwithjoel)\
**Post date:** [July 24, 2024, 1:29pm UTC](https://community.noloco.io/t/comment-tagging-should-respect-user-table-permissions/259/8 "2024-07-24T13:29:46Z")

</div>

Just wanted to contribute how I see this in practical terms (the context aspect of tagging conditions). If they functioned like visibility conditions, it would be absolutely magical.

For example… can tag users whose user record…

(pick your user record field)

- is
- is not
- contains
- does not contain
- etc

(pick the current page’s record or something from \> logged in user)

(pick your field)

Then you can only tag people matching that condition.

**TLDR: Can restrict tagging to users that match a condition related to the current page’s record, or the logged in user’s record.**

---

<div class="post-metadata">

**Author:** ![darragh](https://dub1.discourse-cdn.com/flex005/user_avatar/community.noloco.io/darragh/32/12_2.png) [@darragh](https://community.noloco.io/u/darragh)\
**Post date:** [July 25, 2024, 6:30am UTC](https://community.noloco.io/t/comment-tagging-should-respect-user-table-permissions/259/9 "2024-07-25T06:30:10Z")

</div>

This might actually be a very interesting solution, thanks for the suggestion @buildwithjoel

---

<div class="post-metadata">

**Author:** ![buildwithjoel](https://dub1.discourse-cdn.com/flex005/user_avatar/community.noloco.io/buildwithjoel/32/1537_2.png) [@buildwithjoel](https://community.noloco.io/u/buildwithjoel)\
**Post date:** [May 28, 2025, 8:58pm UTC](https://community.noloco.io/t/comment-tagging-should-respect-user-table-permissions/259/10 "2025-05-28T20:58:21Z")

</div>

This has come up again! Curious if this is in the works or under consideration?

Thanks : )

---

<div class="post-metadata">

**Author:** ![darragh](https://dub1.discourse-cdn.com/flex005/user_avatar/community.noloco.io/darragh/32/12_2.png) [@darragh](https://community.noloco.io/u/darragh)\
**Post date:** [May 29, 2025, 5:38am UTC](https://community.noloco.io/t/comment-tagging-should-respect-user-table-permissions/259/11 "2025-05-29T05:38:56Z")

</div>

Not at the moment @buildwithjoel - still very interested in it, but for 99% of people the permissions works well

---

<div class="post-metadata">

**Author:** ![buildwithjoel](https://dub1.discourse-cdn.com/flex005/user_avatar/community.noloco.io/buildwithjoel/32/1537_2.png) [@buildwithjoel](https://community.noloco.io/u/buildwithjoel)\
**Post date:** [May 30, 2025, 1:46am UTC](https://community.noloco.io/t/comment-tagging-should-respect-user-table-permissions/259/12 "2025-05-30T01:46:18Z")

</div>

Understood. Appreciate the update!

---

<div class="post-metadata">

**Author:** ![Polka75](https://avatars.discourse-cdn.com/v4/letter/p/94ad74/32.png) [@Polka75](https://community.noloco.io/u/Polka75)\
**Post date:** [August 1, 2025, 11:43am UTC](https://community.noloco.io/t/comment-tagging-should-respect-user-table-permissions/259/13 "2025-08-01T11:43:54Z")

</div>

Hi,

Adding my 2 cents as well on the matter.  
A “by role” permission is not ideal in our context.  
Would it be possible to add an option to simply deactivate mentions entirely from a comment section? This way we would lose some features but protect ourselves from the weirdness of letting users mention people they have no business with

---

<div class="post-metadata">

**Author:** ![buildwithjoel](https://dub1.discourse-cdn.com/flex005/user_avatar/community.noloco.io/buildwithjoel/32/1537_2.png) [@buildwithjoel](https://community.noloco.io/u/buildwithjoel)\
**Post date:** [August 6, 2025, 7:21pm UTC](https://community.noloco.io/t/comment-tagging-should-respect-user-table-permissions/259/14 "2025-08-06T19:21:05Z")

</div>

@Polka75

Absolutely would love to see a tagging deactivation option that lives in the config for any given comments element. I’ve historically had to solve for this by turning off access to Noloco user records entirely (when using an external user list, i.e. Airtable) which is not an ideal workaround.

---

<div class="post-metadata">

**Author:** ![darragh](https://dub1.discourse-cdn.com/flex005/user_avatar/community.noloco.io/darragh/32/12_2.png) [@darragh](https://community.noloco.io/u/darragh)\
**Post date:** [August 11, 2025, 7:55am UTC](https://community.noloco.io/t/comment-tagging-should-respect-user-table-permissions/259/15 "2025-08-11T07:55:40Z")

</div>

This is an interesting suggestion @buildwithjoel ! We’ll take a look at something like this over the next couple of weeks

---

<div class="post-metadata">

**Author:** ![darragh](https://dub1.discourse-cdn.com/flex005/user_avatar/community.noloco.io/darragh/32/12_2.png) [@darragh](https://community.noloco.io/u/darragh)\
**Post date:** [August 28, 2025, 9:57am UTC](https://community.noloco.io/t/comment-tagging-should-respect-user-table-permissions/259/16 "2025-08-28T09:57:15Z")

</div>

Hey @buildwithjoel ! Good news, we’ve added this toggle that lets you disable mentions in comments entirely on certain pages.

It should give you slightly more control over your comments!

---

<div class="post-metadata">

**Author:** ![buildwithjoel](https://dub1.discourse-cdn.com/flex005/user_avatar/community.noloco.io/buildwithjoel/32/1537_2.png) [@buildwithjoel](https://community.noloco.io/u/buildwithjoel)\
**Post date:** [September 5, 2025, 7:57pm UTC](https://community.noloco.io/t/comment-tagging-should-respect-user-table-permissions/259/17 "2025-09-05T19:57:50Z")

</div>

Thank you!! To clarify, what do you mean by “certain pages”?

---

<div class="post-metadata">

**Author:** ![darragh](https://dub1.discourse-cdn.com/flex005/user_avatar/community.noloco.io/darragh/32/12_2.png) [@darragh](https://community.noloco.io/u/darragh)\
**Post date:** [September 8, 2025, 6:44am UTC](https://community.noloco.io/t/comment-tagging-should-respect-user-table-permissions/259/18 "2025-09-08T06:44:00Z")

</div>

I more meant that it’s not a global toggle, so on any comments settings (whether it’s in the sidebar or the component) you can disable tagging in those comments.

---

<div class="post-metadata">

**Author:** ![buildwithjoel](https://dub1.discourse-cdn.com/flex005/user_avatar/community.noloco.io/buildwithjoel/32/1537_2.png) [@buildwithjoel](https://community.noloco.io/u/buildwithjoel)\
**Post date:** [September 8, 2025, 6:34pm UTC](https://community.noloco.io/t/comment-tagging-should-respect-user-table-permissions/259/19 "2025-09-08T18:34:56Z")

</div>

Got it - thanks for that!
