Forum Discussion
Row Level Security - Shared Dataset Two Reports
- 2 years ago
I guess I am jaded because we always allow build access. As soon as you do that report "security" becomes obsolete.
Our reasoning is that our job is to help users get insights, not to prevent them from getting access.
Are you just talking about hiding a report in the Workspace App? I'm asking only about sharing reports directly. RLS does not give access to a report.
I have always understood it as:
1. RLS controls what data you can see (filters the model)
2. Report sharing controls if you can access the report**
**As long as they don't have a Workspace role or have access through the Workspace app
If user1 has an RLS role for 1 dataset but does not have access to the report, then in "Test as role" it says "This user does not have access to the dataset or report". See my example below.
RLS Role:
View in "Test as Role"
When I grant the user "Read" access to the Report, the role works.
Granting user read access:
No error and report displays:
Going back to my original question -
I don't understand why "Test as Role" behaves differently with one report versus two reports connected to the same dataset.
test2 report is not shared with the user. But the same error shown above does not show.
I guess I am jaded because we always allow build access. As soon as you do that report "security" becomes obsolete.
Our reasoning is that our job is to help users get insights, not to prevent them from getting access.