Manoharch's avatar
Manoharch
New Member
1 month ago
Status:
New

Folder level Permissions: Power BI

Workspace folders solved organization but not access control. Permissions today exist only at the workspace level (Admin, Member, Contributor, Viewer) or per individual item. Everything in between is missing.

 

The result is workspace sprawl. Teams create dozens of workspaces purely to separate audiences, then carry the cost: duplicated semantic models, fractured lineage, deployment pipelines multiplying, capacity assignment overhead, and inconsistent governance across near-identical containers.

 

Proposed capability:

Allow a folder inside a workspace to carry its own access assignment, inherited from the workspace by default and optionally overridden:

 

Assign security groups or users to a folder with a role scoped to that folder’s contents

Inheritance on by default, with an explicit “break inheritance” action

Restricted folders hidden from users without access, not just greyed out

Support via REST API and PowerShell for automation and audit

Folder permission changes surfaced in the Fabric audit log

Nested folder inheritance that follows the parent chain

 

Use cases:

Dev and test content kept invisible to business users inside the same workspace

A shared workspace where Finance, HR, and Operations each see only their folder

Certified content in a locked folder while a sandbox folder stays open to analysts

Migrations from Tableau, where project-level folder security is standard and has no equivalent target structure in Power BI

 

Impact:

Fewer workspaces to govern, one semantic model instead of several copies, simpler pipeline design, and a security model that matches how organizations already think about content hierarchy.

1 Comment

  • Interesting point. Folder-level permissions could definitely help reduce workspace sprawl, especially for organizations with multiple teams sharing the same workspace. I’m curious how others see the trade-off between simpler workspace management and more granular security. Would this actually solve a common pain point in large Power BI environments?

Recent ideas