# Data entitlements > Grant teams access to specific data sources and understand how tenant and team isolation is enforced by Postgres row-level security. *[View this page in the Flax docs](https://flax-analytics.com/docs/administration/data-entitlements)* Data entitlements decide which data sources a team can query. Together with organization-level isolation, they ensure people only reach the data they are meant to. This is an admin-only capability. ## Entitling a team to a source An admin grants a team access to a data source from the team's settings. Two source types are supported: | Source type | What it grants | | --- | --- | | `semantic_project` | Access to a semantic model project. You can optionally scope the grant to specific model names. | | `connection` | Access to a warehouse connection. | A team can only query models and connections it has been entitled to. Revoking a grant removes that access immediately. ## Isolation with Postgres row-level security Flax enforces isolation in the database itself using Postgres **row-level security (RLS)**, not just in application code: - **Tenant isolation.** Every row carries its organization, and RLS policies restrict each request to its own organization's rows. Data from one organization can never be read from another. - **Team scoping.** Access to team-owned content and entitlements is evaluated against the caller's team membership within the same tenant. Because these checks live in Postgres, they apply uniformly to every query path — the app, the API, scheduled deliveries, and embeds — so there is no surface where they can be bypassed. ## Row-level filtering of query results Entitlements decide *whether* a team can query a source. To filter *which rows* individual users see within a source — for example, restricting a regional manager to their region — combine entitlements with row-access filters driven by [user attributes](/docs/administration/user-attributes). ## Related - [Row-access filters](/docs/modeling/row-access-filters) - [User attributes](/docs/administration/user-attributes) - [Teams and RBAC](/docs/administration/teams-and-rbac)