Forum Discussion
Sharing semantic models through intermediary
- 8 months ago
Hi DouweMeer ,
Thanks for the follow up.
Assigning an AD group with read access may not prevent a user with reshare and build from granting additional permissions. If they choose to share and allow build, that direct permission might still apply alongside the group’s read access, since permissions are handled in an additive way.If you want to ensure only read access is propagated, the reshare permission would need to be restricted.
Please reach out for further assistance.
Thank you.
Never ever grant "reshare" to anyone.
"If you don't want users to access your data the best approach is to not have the data in the first place."
By retaining the "share" permissions to yourself you have at least some semblance of DLP control.
It's not so much the issue that these people have access to the data as that the data is of concern, more that we wouldn't want this individuals try to extract it themselves. 1, they are not paid to do it themselves, 2, they are not expected to be capable knowing how to.
More a case of governance, making sure that who has build rights and can publish his report, knows what he's doing.