Hide from, and access only to
Two rules that look alike on screen and promise two completely different things.
Hide from: what appears in the portal
Visibility decides what a user meets. A hidden page disappears from the menu and from the address, and a hidden widget is removed from the page. The rule lives in the page editor, where the content is, and it does not hold data back: permissions do that.
The panel answers the interesting question while you are setting the rule: 6 of 7 see the page, and here are the names of the ones who do not. If the rule closes it for everyone, the panel says so before you save.
Access only to: which records the user may see
Narrowing is a security boundary. It is enforced on every read and every write, and it cannot be undone by removing a widget. It lives on the access, one row per app.
A narrowing can close a view rather than shrink it. If a widget cannot be narrowed on the axis you choose, it goes empty for the user, and that is said before you save: the widget is named along with its page, and the button carries it ("narrow, and close 1 widget").