Forum Discussion

Jolien's avatar
Jolien
Advocate I
6 years ago
Solved

Security on multiple reports in one app

Kind stranger,

 

I've created multiple reports (each with their own dataset) in one workspace. I've published them in the same app, but now I'd like to add restrictions to who can see which report.

 

To make matters concrete:

  • Workspace CustomerName
  • Reports in CustomerName
    • General Report
    • Management Report
  • Datasets in CustomerName
    • General Reporting
    • Management Reporting

I've applied RLS to the General Report, so project managers can only see data for their onw projects.

However, the current situation allows them to see all data in the management report.

I'd like to add security to the reports, so only a select group of people (management) can see both reports and all other users (project managers) can only see the general report (with RLS applied).

 

Can anyone help me with this?

  • I eventually solved this by creating 2 workspaces, adding each report to its own workspace and restricting access to the apps built on the workspaces.

    I've made 2 links available, one to the management-app and one to the general-app. Each person will get a "restricted" error on one of both links (on which one depends on their profile).

     

    Thank you for the provided help!

     

    Kind regards,

    Jolien

6 Replies

  • nickyvv's avatar
    nickyvv
    Most Valuable Professional

    Hi Jolien,

    I think the option that would work is the following:

    You can leave everything in the same workspace. But publish the app without the Management report. Then give management the Viewer Role on the workspace. They will be able to view the contents of the workspace (both reports), and the rest will only see the General Report in the app.

    Let me know if that works for you. I'm not sure if everyone has a pro license or that you use Premium capacity, that's not clear from your question. But this should work, regardless of how you have implemented it now.

     

    Did this help you or did I answer your question?
    Then please give kudos or mark my post as a solution!
    My blog: nickyvv.com
    Twitter: @NickyvV

    • Jolien's avatar
      Jolien
      Advocate I

      Hi nickyvv ,

       

      Thank you for your quick reply.

      That sounds like a good workaround, but to me it kind of defies the use of the app as management would have to go from the app to the workspace every time. Isn't there a solution that doesn't require them to leave the app?

      Most of them have no experience at all with the workspace + navigating from app to workspace is quite tiresome.

       

      Kind regards,

      Jolien

      • v-xuding-msft's avatar
        v-xuding-msft
        Community Support

        Hi Jolien ,

        You could assign contributor or member roles to the group of people (management). They can view all the reports in the workspace because of editing capability. And you could add other users (project managers) to a viewer role.  Then add the group of people (management) in the security of the reports that you don't want users to view. In this way, project managers will get the error massage below in those reports.

        It is a little complicated way. In Service, there is not an option can hide reports or make users not view reports directly. So, hope this can help you.

         

        Best Regards,

        Xue Ding

        If this post helps, then please consider Accept it as the solution to help the other members find it more quickly.

  • I eventually solved this by creating 2 workspaces, adding each report to its own workspace and restricting access to the apps built on the workspaces.

    I've made 2 links available, one to the management-app and one to the general-app. Each person will get a "restricted" error on one of both links (on which one depends on their profile).

     

    Thank you for the provided help!

     

    Kind regards,

    Jolien

  • Would it have been feasible to feature engineer a new column(s) with row security classes as categorical values?