Forum Discussion

KarenL7's avatar
KarenL7
Advocate V
23 days ago
Solved

Org App - Audiences - Remove Permissions

Hi   I have currently started using Org Apps with audiences, and we have been deploying them.     When they deploy to the workspace, they automatically pick up the permissions from the workspace ...
  • tayloramy's avatar
    23 days ago

    Hi KarenL7

     

    It is not possible to prevent someone with viewer permissions on the workspace from viewing the report. Viewer grants them access to see all reports in the workspace. 

     

    If you want permissions to be handled solely by audiences, I recommend removing individual workspace permissions.  

  • DataTako's avatar
    22 days ago

    Makes sense, and it's a common trip-up. The short version: you can't remove those workspace groups from the audience, because their access isn't coming from the audience at all. It's coming from their workspace role.

     

    Anyone with a workspace role (admin, member, contributor or viewer) automatically gets access to the app and its audiences. Audience membership only adds people on top of that, it can't subtract someone who already has workspace access. So the viewer groups you're seeing in the audience are there because they're workspace viewers, not because of the audience settings.

     

    The fix is at the workspace level, not the audience. Keep workspace roles limited to the people who actually build and maintain the reports, and take the consumer groups out of the workspace viewer role. Then give those consumers access only through the specific audience. Once a group's only route to the content is the audience, the audience genuinely controls who sees what.

     

    So: pull the consumer groups out of the workspace roles, add them to the audience instead, and the workspace-wide access falls away.

     

    Out of interest, how big is the org, and how are you licensing the viewers, all on Pro, or on an F capacity?