Column-level Permissions

更新时间:
复制 MD 格式

Column-level permissions let you control access to specific fields across your organization. Use them to apply data masking or hide sensitive fields such as phone numbers and ID cards.

Scenarios

To protect sensitive data such as phone numbers and ID cards, configure Data Masking or Do Not View rules in column-level permissions at the organization level. After rules take effect, users can only view field values allowed by the rules.

Limits

  • Only organization administrators and custom-role users with the enterprise security feature can configure organization-level column-level permissions.

  • This feature requires the updated version of row and column permissions. If you use the previous version, upgrade to the new version.

  • A maximum of 10 column-level permission rules can be created.

Procedure

  1. Log on to the Quick BI console or the .

  2. Go to the column-level permissions settings page.

    image

  3. Click Add Rule and configure the following settings.

    image

    Configuration item

    Description

    ① Rule Name

    Enter a custom rule name. Duplicate names are not allowed.

    ② Field Name

    Fields matching the specified name are masked. Separate multiple field names with commas. Duplicates are not allowed.

    ③ Set Rule

    • Do Not View

      Fields set to Do Not View show "- -" in cross tables and are hidden in other charts.

    • Data Masking

      Specify fields to mask. The system blurs sensitive data and displays masked values in dashboards, workbooks, and downloads.

    ④ Who is it effective for

    Choose Effective for Everyone, Valid for Selected Users Only, or Invalid for Selected Users Only.

    Users must have both dataset and organization-level permissions to view the data.

    Rules for each scope are described in Effect Display and Rule Description.

  4. Click Complete.

Effect display and rule description

Do Not View

  • Set Rule

    Example: Create a rule to hide the customer name field.

    image

  • Effect Display

    After the rule takes effect, the field shows "- -" in cross tables and is hidden in other charts such as bar charts.

    image

Data Masking

  • Set Rule

    Example: Create a rule to mask phone numbers for all users.

    image

    You can also create custom masking rules in Data Masking.

    image

  • Effect Display

    After the rule takes effect, all users see only the masked phone numbers.

    image

Effect description

Scope

Behavior

Effective for Everyone

For the specified fields:

  • The configured rules apply to all users.

Valid for Selected Users Only

For the specified fields:

  • Specified users or user groups:

    Restricted by the configured rules. Do Not View fields are hidden; masked fields show only masked values.

  • Other users:

    Not restricted. Full field values are visible.

Invalid for Selected Users Only

For the specified fields:

  • Specified users or user groups:

    Not restricted. Full field values are visible.

  • Other users:

    Restricted by the configured rules. Do Not View fields are hidden; masked fields show only masked values.

Usage notes

  • Users must have both dataset and organization-level permissions to view data.

  • Organization-level column-level permissions take precedence over dataset permissions. When fields are governed by organization-level rules, masking applies regardless of dataset-level settings.

For an explanation of column-level permissions within a dataset, refer to Column-level Permissions.

Manage column-level permissions

  1. Access the column-level permissions settings page.

    image

  2. On the management page, edit (①) or delete (②) existing permission rules. image