I have an app where regular users report accidents within the company. HR has requested that all users are able to view the accident reports but unless it's their own report or they're a manager then various information is redacted/hidden such as names, etc.
Would this be a policy/authorization thing or how would you approach this?
To me, policies and gates are typically for the entire record, not necessarily for hiding specific details but maybe I'm wrong?