Forum Discussion
Org App - Audiences - Remove Permissions
- 1 month ago
Hi KarenL7,
It is not possible to prevent someone with viewer permissions on the workspace from viewing the report. Viewer grants them access to see all reports in the workspace.
If you want permissions to be handled solely by audiences, I recommend removing individual workspace permissions.
- 1 month ago
Makes sense, and it's a common trip-up. The short version: you can't remove those workspace groups from the audience, because their access isn't coming from the audience at all. It's coming from their workspace role.
Anyone with a workspace role (admin, member, contributor or viewer) automatically gets access to the app and its audiences. Audience membership only adds people on top of that, it can't subtract someone who already has workspace access. So the viewer groups you're seeing in the audience are there because they're workspace viewers, not because of the audience settings.
The fix is at the workspace level, not the audience. Keep workspace roles limited to the people who actually build and maintain the reports, and take the consumer groups out of the workspace viewer role. Then give those consumers access only through the specific audience. Once a group's only route to the content is the audience, the audience genuinely controls who sees what.
So: pull the consumer groups out of the workspace roles, add them to the audience instead, and the workspace-wide access falls away.
Out of interest, how big is the org, and how are you licensing the viewers, all on Pro, or on an F capacity?
Makes sense, and it's a common trip-up. The short version: you can't remove those workspace groups from the audience, because their access isn't coming from the audience at all. It's coming from their workspace role.
Anyone with a workspace role (admin, member, contributor or viewer) automatically gets access to the app and its audiences. Audience membership only adds people on top of that, it can't subtract someone who already has workspace access. So the viewer groups you're seeing in the audience are there because they're workspace viewers, not because of the audience settings.
The fix is at the workspace level, not the audience. Keep workspace roles limited to the people who actually build and maintain the reports, and take the consumer groups out of the workspace viewer role. Then give those consumers access only through the specific audience. Once a group's only route to the content is the audience, the audience genuinely controls who sees what.
So: pull the consumer groups out of the workspace roles, add them to the audience instead, and the workspace-wide access falls away.
Out of interest, how big is the org, and how are you licensing the viewers, all on Pro, or on an F capacity?
- KarenL71 month ago
Advocate V
Hi DataTako
Yes you are correct, I think we saw this with the workspace app - but it was not as obvious as it is in the new structure in the org app. So we will remove them from the workspace - but we will need to do this in new areas going forward as we are just moving over to org apps now as we still have some people accessing via the workspace.
Everyone is able to view reports we do not have this issue so we will use this solution going forward.
Thanks for your help.
Karen