With GraphQL, you can think of each field as a tiny endpoint, and you do access control on that in the same way as before.
It turns out that while GraphQL allows the frontend developers to select the data they need, that doesn't result in an unlimited set of queries. You often get a number of queries which is similar to what you would get if you hand-coded specific endpoints for different UI views, which turns out to be a common pattern outside of GraphQL.
> What happens if the user doesn't have access to part of the requested data
In this case, the gateway just falls back to the underlying server implementation, and it's a cache miss.