What access rights control
Access management defines for whom data sources, dashboard groups, and individual dashboards are restricted. By default, all access is allowed.
You do not work with one global role matrix. Instead, you define individual restrictions per resource.
Difference from roles
Roles and access restrictions control different things:
- Roles define which functions a person is generally allowed to use.
- Access restrictions define which specific data source, dashboard group, or dashboard is restricted for whom.
Important: Anyone who can see a resource can usually also edit it. The exception is the Viewer role.
How the model works
Each access restriction consists of three parts:
- Category: data source, dashboard group, or dashboard
- Resource: one or more specific items from that category
- Restricted for: roles or individual people
There is also a simple inheritance switch:
- A restricted dashboard group can pass its restriction to contained dashboards.
- A restricted data source can pass its restriction to dependent dashboards.
How to set up an access restriction
- Open Administration. You need the Owner or Admin role.
- Open the Restrict data access tile.
- Click Create access restriction.
- Choose the category.
- Choose one or more resources.
- Choose the roles or people the resource should be restricted for.
- Enable or disable inheritance if needed.
- Save the restriction.
Visible behavior for affected people
- Restricted dashboard groups are hidden.
- Restricted dashboards are hidden.
- Restricted data sources remain visible, but are disabled and show a note that rights are missing.
Important notes
The restriction is enforced server-side and takes effect immediately. Changes are stored per resource. If there is a conflict, Zweigen reloads the current state. Owners and Admins keep access to Administration itself.
Related topics
- Role Management - Which roles exist and what they are allowed to do
- Administration - Open access management in the Administration area
All Data. One system.
Contact
We are happy to help and advise. Send us an email at hi@zweigen.cloud or visit our socials.