-- Add visibility column to data_tables ALTER TABLE data_tables ADD COLUMN IF NOT EXISTS visibility VARCHAR(20) DEFAULT 'restricted'; -- Create data_table_access_rules (role-based access to directories, analogous to form_access_rules) CREATE TABLE IF NOT EXISTS data_table_access_rules ( id SERIAL PRIMARY KEY, table_id INT NOT NULL REFERENCES data_tables(id) ON DELETE CASCADE, organization_id INT NOT NULL REFERENCES organizations(id) ON DELETE CASCADE, target_type VARCHAR(10) NOT NULL CHECK (target_type IN ('user', 'role')), target_id INT NOT NULL, access_level VARCHAR(20) NOT NULL DEFAULT 'reader' CHECK (access_level IN ('reader', 'editor', 'admin')), created_at TIMESTAMP DEFAULT NOW(), UNIQUE (table_id, target_type, target_id) ); CREATE INDEX IF NOT EXISTS idx_data_table_access_rules_table ON data_table_access_rules(table_id); CREATE INDEX IF NOT EXISTS idx_data_table_access_rules_org ON data_table_access_rules(organization_id);