kayu - what permission does the user passed in effectiveUsername need on the semantic model?Our setup: a service principal that is Admin of the workspace calls Execute DAX Queries with effectiveUsername and roles, on a Fabric-capacity model with RLS roles.
What we see:- The effective user is only a member of the RLS role, with no other access to the model: HTTP 200 with an error rowset, FaultCode 0xc114004c ("the database does not exist, or you do not have permissions").- The effective user has Read on the model: it works, and RLS filters the rows correctly (each user saw only their own region).- Adding Build made no difference.
So is Read on the semantic model the minimum the effective user needs, or is something else causing the error?
The API reference says "the user must have dataset read and build permissions", but it doesn't say whether "the user" is the calling service principal or the effective user. Could that be clarified in the docs?