Forum Discussion
Org App - Audiences - Remove Permissions
- 23 days ago
Hi KarenL7,
It is not possible to prevent someone with viewer permissions on the workspace from viewing the report. Viewer grants them access to see all reports in the workspace.
If you want permissions to be handled solely by audiences, I recommend removing individual workspace permissions.
- 22 days ago
Makes sense, and it's a common trip-up. The short version: you can't remove those workspace groups from the audience, because their access isn't coming from the audience at all. It's coming from their workspace role.
Anyone with a workspace role (admin, member, contributor or viewer) automatically gets access to the app and its audiences. Audience membership only adds people on top of that, it can't subtract someone who already has workspace access. So the viewer groups you're seeing in the audience are there because they're workspace viewers, not because of the audience settings.
The fix is at the workspace level, not the audience. Keep workspace roles limited to the people who actually build and maintain the reports, and take the consumer groups out of the workspace viewer role. Then give those consumers access only through the specific audience. Once a group's only route to the content is the audience, the audience genuinely controls who sees what.
So: pull the consumer groups out of the workspace roles, add them to the audience instead, and the workspace-wide access falls away.
Out of interest, how big is the org, and how are you licensing the viewers, all on Pro, or on an F capacity?
Hi KarenL7,
It is not possible to prevent someone with viewer permissions on the workspace from viewing the report. Viewer grants them access to see all reports in the workspace.
If you want permissions to be handled solely by audiences, I recommend removing individual workspace permissions.
- KarenL722 days agoAdvocate V
Thank you for your reply, yes this is a very good idea to remove workspace permissions - I think we should do this from now on - we are just moving over to org apps and have been so used to adding in workspace permissions as a normal route that we will do this.
Even with the workspace app we used we did not seem to have many issues - with the new structure in the org app you can really see the permission structure.
Thanks
Karen