Forum Discussion
Security on multiple reports in one app
- 6 years ago
I eventually solved this by creating 2 workspaces, adding each report to its own workspace and restricting access to the apps built on the workspaces.
I've made 2 links available, one to the management-app and one to the general-app. Each person will get a "restricted" error on one of both links (on which one depends on their profile).
Thank you for the provided help!
Kind regards,
Jolien
Hi Jolien,
I think the option that would work is the following:
You can leave everything in the same workspace. But publish the app without the Management report. Then give management the Viewer Role on the workspace. They will be able to view the contents of the workspace (both reports), and the rest will only see the General Report in the app.
Let me know if that works for you. I'm not sure if everyone has a pro license or that you use Premium capacity, that's not clear from your question. But this should work, regardless of how you have implemented it now.
Did this help you or did I answer your question?
Then please give kudos or mark my post as a solution!
My blog: nickyvv.com
Twitter: @NickyvV
Hi nickyvv ,
Thank you for your quick reply.
That sounds like a good workaround, but to me it kind of defies the use of the app as management would have to go from the app to the workspace every time. Isn't there a solution that doesn't require them to leave the app?
Most of them have no experience at all with the workspace + navigating from app to workspace is quite tiresome.
Kind regards,
Jolien
- v-xuding-msft6 years ago
Community Support
Hi Jolien ,
You could assign contributor or member roles to the group of people (management). They can view all the reports in the workspace because of editing capability. And you could add other users (project managers) to a viewer role. Then add the group of people (management) in the security of the reports that you don't want users to view. In this way, project managers will get the error massage below in those reports.
It is a little complicated way. In Service, there is not an option can hide reports or make users not view reports directly. So, hope this can help you.
Best Regards,
Xue Ding
If this post helps, then please consider Accept it as the solution to help the other members find it more quickly.
- Jolien6 years ago
Advocate I
Hi v-xuding-msft ,
Thank you for your help.
Now I have:
- Workspace Acces:
- Admins -as- Admin
- Management -as- Viewer
- Project Managers - Not added
- General Reporting (dataset) Security:
- Role: Project Manager - Added Project Managers
- General Reporting (dataset) Permissions:
- Admins -as- Admin (Owner)
- Management -as- Viewer, App (build)
- Project Managers -as- App
- Management Reporting (dataset) Permissions:
- Admins -as- Admin (Owner)
- Management -as- Viewer, App (build)
- Project Managers -as- App
- App Permissions:
- Specific individuals or group - Added Project Managers (build permission unchecked)
I've checked with a PM and if I don't add him to the app permissions, he gets an error saying something like "you don't have enough access, request permission". If I do add him (as per above), he can still see both the general report (with only data from his projects) and management report (with all data from all projects). What am I doing wrong?
Plus, doesn't the "(build)" in the dataset permissions mean they have too much access? I don't want management to edit reports, only read them. It seems like I can't remove the build access without removing them from the workspace.