Skip to main content

Permissions and Access in Analytics: Who Can See What

Covers access roles, sharing, folder inheritance, access requests, and access warnings for dashboards and workbooks.

Dashboards and workbooks in Analytics are only visible to the people you choose to share them with. This article covers how access works, how to share content, and how to troubleshoot common access issues, such as a colleague seeing a blank tile on a supplier spend dashboard.

Access roles

Access to a document, such as a dashboard or workbook, is controlled by an access role. Roles can be assigned to individual users, to user groups, or to your whole organization.

Role

What it allows

No Access

Cannot view or interact with the document at all

Viewer

Can view dashboards, such as a published Supplier Spend dashboard, but cannot open or edit the underlying workbook

Editor

Can view and explore the workbook, and update dashboards and workbooks

Manager

Everything an Editor can do, plus managing permissions on the document and receiving access requests

Owner

Full control of the document. Every document needs at least one owner at all times

A document can have more than one owner. If someone is the only owner of a document, their access can't be downgraded or removed until another owner is assigned.

Folders work similarly, but with one important difference: sharing a folder gives that access to everything inside it, and folder-level roles also control who can add or remove content from the folder itself.

Sharing a document or folder

  1. Open the dashboard, workbook, or folder you want to share.

  2. Click the Share icon near the top right corner.

  3. To share with specific people, click the Share with users or groups field and select the users or groups you want, then choose an access role and click Share.

  4. To share with everyone in your organization at once, use the access role dropdown in the Organization row instead. For example, you might give your whole Procurement team Viewer access to a spend dashboard, while giving your analytics team Editor access to the underlying workbook.

As a general rule of thumb, it's best to give people the least permissive role that covers what they need. A stakeholder who only needs to check spend figures should be a Viewer, not an Editor.

How access is inherited

Content placed inside a folder inherits that folder's access role by default. A document or subfolder can be given a more open role than its parent folder, but never a more restrictive one.

For example, if a "Procurement Reports" folder is shared at Editor level, nothing inside it can be locked down to Viewer only. But if that same folder has No Access set, individual dashboards inside it can still be shared more openly, such as a specific supplier scorecard being shared at Viewer level with a wider audience.

Good to know: Folder names are always visible to anyone who can see at least one item inside that folder, even if they don't have access to the folder itself.

Requesting access

If someone tries to open a dashboard they don't have access to, such as a supplier risk dashboard, they can request access directly. The document's owner and any managers will get a notification and can approve or deny the request from the document's Share dialog.

Controlling what viewers can do

Beyond basic view or edit access, document owners and managers can turn specific abilities on or off for a document, such as whether viewers are allowed to schedule email deliveries or duplicate the dashboard. These settings live in File > Document Settings, or under Settings in the Share dialog.

Access warnings

If you're editing a dashboard and see a yellow asterisk (*) on a tile, it means some of your viewers won't be able to see that tile's data due to their permissions. This warning is only visible to editors. Viewers with lower access will just see a blank tile, with no indication anything is missing.

Common causes include a tile being built from raw SQL rather than a governed data model, or a tile referencing fields that a particular viewer isn't permitted to see.

Did this answer your question?