Authorization settings

Updated at:

In Quick BI Enterprise Standard and Advanced Edition, you can use organization-level settings to control public access and collaborative authorization for data works. A permission administrator can enable or disable authorization entry points for all workspaces with a single click and configure default permissions for data works.

Use cases

Scenario

Expected outcome

Configure permissions for data works

These settings control whether the Can be made public and Can be authorized options are available in workspaces, which determines whether data works in your organization can be made public, shared, or granted permissions through collaborative authorization.

image

  • If you select Authorize all users in the organization for the Works Authorization option, you can grant permissions to any member of your organization.

  • If you select Authorize only users within the workspace for the Works Authorization option, you can grant permissions only to individual members of the workspace.

Note

Data works include BI portals, dashboards, workbooks, self-service queries, ad hoc queries, data screens, data entries, exploratory analyses, and Q reports.

When you enable the public access and authorization options, the corresponding permission settings appear in the workspace.

  • Can be made public: When enabled, the following data works can be made public: dashboards, workbooks, self-service queries, ad hoc queries, data screens, data entries, and Q reports.

  • Can be authorized: When enabled, permissions can be granted for the following data works: BI portals, dashboards, workbooks, self-service queries, ad hoc queries, data screens, data entries, exploratory analyses, and Q reports.

image

Set default authorization for workspace resources

Configure the default permissions for data works within newly created workspaces.

You can set default authorization for data works (BI portals, dashboards, workbooks, self-service queries, ad hoc queries, data screens, and data entries), datasets, and data sources.

Note

Changes to the Default authorization for workspace resources settings apply only to workspaces created after you save the changes.

  • View and export data works: You can set the default to either All workspace members or Report owner only.

    This setting determines whether the Works are viewable by all workspace members by default option is selected when a new workspace is created.

    image

  • Edit data works: You can set the default to either All workspace members (for members with data works edit permission) or private.

    This setting determines the default Edit permission in the collaborative authorization panel for new reports.

    • If the default is private, the edit permission defaults to private, meaning unauthorized users cannot edit the report.

    • If the default is All workspace members (for members with data works edit permission), all workspace members with the required permission can edit the report.

    image.png

  • Edit datasets: You can set the default to either All workspace members (for members with dataset edit permission) or private.

    This setting determines the default Edit permission in the collaborative authorization panel for new datasets.

    • If the default is private, the edit permission defaults to private, meaning unauthorized users cannot edit the dataset.

    • If the default is All workspace members (for members with dataset edit permission), any workspace member with dataset editing permissions can edit the dataset.

  • Use datasets: You can set the default to either All workspace members (for members with dataset use permission) or specified members.

    This setting determines the default use permission in the collaborative authorization panel for new datasets.

    • If the default is specified members, only specified users can use the dataset by default.

    • If the default is All workspace members (for members with dataset use permission), the use permission defaults to All workspace members (for members with dataset use permission), meaning members with dataset use permissions can use the dataset.

    image.png

  • Edit data sources: You can set the default to either All workspace members (for members with data source edit permission) or private.

    This setting determines the default Edit permission in the collaborative authorization panel for new data sources.

    • If the default is private, the edit permission defaults to private, meaning unauthorized users cannot edit the data source.

    • If the default is All workspace members (for members with data source edit permission), the edit permission defaults to All workspace members (for members with data source edit permission), meaning members with data source editing permissions can edit the data source.

  • Use data sources: You can set the default to either All workspace members (for members with dataset use permission) or specified members.

    This setting determines the default use permission in the collaborative authorization panel for new data sources.

    • If the default is specified members, the use permission defaults to specified members, meaning only specified users can use the data source.

    • If the default is All workspace members (for members with dataset use permission), the use permission defaults to All workspace members (for members with dataset use permission), meaning members with dataset use permissions can use the data source.

    image.png

Access the feature

As a permission administrator, log on to the Quick BI console. Follow the path in the figure to the organization-level Authorization Settings page.image

Configure public access and authorization options

These settings control whether options for public access, sharing, and collaborative authorization are available for all workspaces in your organization.

  • Data works

    Data works include BI portals, dashboards, workbooks, self-service queries, ad hoc queries, data screens, data entries, exploratory analyses, and Q reports.

    • When Can be made public and Can be authorized are selected, the Works can be made public and Works can be authorized options appear in the Feature Permissions section of a workspace's settings.

      You can then enable or disable Works can be made public or Works can be authorized within each workspace as needed. For more information, see Create and manage a workspace.

    • If you clear Can be made public and Can be authorized, the Works can be made public and Works can be authorized options are hidden in the Feature Permissions section.

      image

      In this case, resources in all workspaces in your organization cannot be made public, shared, or granted permissions through collaborative authorization.

  • Dataset

    • Can be authorized: Governs collaborative authorization for datasets across all workspaces.

    • Row-level and column-level permissions can be authorized: Governs collaborative authorization for row-level and column-level permissions across all workspaces, including for datasets.

  • Data source

    Can be authorized: Governs collaborative authorization for data sources across all workspaces.

Default authorization duration

You can set the duration to 1 day, 3 days, 1 week, 1 month, or a custom period.

image

Configure default authorization for workspace resources

These settings configure the default permissions for data works, datasets, and data sources in new workspaces.

Note

Data works include BI portals, dashboards, workbooks, self-service queries, ad hoc queries, data screens, data entries, exploratory analyses, and Q reports.

The following table describes the permissions that are available for different types of resources.

Resource type

Permission type

Data works

View and export data works

Edit data works

Dataset

Edit datasets

Use datasets

Data source

Edit data sources

Use data sources

You can configure default values for different permission types.

Important

These settings affect only resources in workspaces created after you save the changes. Existing workspace resource permissions are not affected.

  • View and export data works: You can set the default to either All workspace members or Report owner only.

    This setting controls the default selection for the Works are viewable by all workspace members by default option in new workspaces.

    • If the default is set to All workspace members, this option is selected by default.

    • If the default is set to Report owner only, this option is not selected by default.

    image

    • If you select All workspace members, reports in the workspace can be viewed and exported by all members.

    • If you select Report owner only, unauthorized users cannot view reports in the workspace.

  • Edit data works: You can set the default to either All workspace members (for members with data works edit permission) or private.

    This setting determines the default edit permission in the collaborative authorization panel for new reports.

    image.png

    • If you select All workspace members (for members with data works edit permission), reports in the workspace can be edited by all members with edit permissions by default.

    • If you select private, unauthorized members cannot edit new reports by default.

      To grant edit permissions on a report, see Grant permissions on data works.

  • Edit datasets: You can set the default to either All workspace members (for members with dataset edit permission) or private.

    This setting determines the default Edit permission in the collaborative authorization panel for new datasets.

    • If the default is private, the edit permission defaults to private, meaning unauthorized users cannot edit the dataset.

    • If the default is All workspace members (for members with dataset edit permission), any workspace member with dataset editing permissions can edit the dataset.

    image.png

    • If you select All workspace members (for members with dataset edit permission), datasets in the workspace can be edited by all members with dataset editing permissions by default.

    • If you select private, unauthorized members cannot edit datasets in the workspace by default.

      To grant edit permissions on a dataset, modify the edit permission attribute and grant authorization. For more information, see Grant edit permissions on a dataset.

  • Use datasets: You can set the default to either All workspace members (for members with dataset use permission) or specified members.

    This setting determines the default use permission in the collaborative authorization panel for new datasets.

    • If the default is specified members, only specified users can use the dataset by default.

    • If the default is All workspace members (for members with dataset use permission), the use permission defaults to all workspace members, meaning members with dataset use permissions can use the dataset.

    image.png

    • If you select All workspace members (for members with dataset use permission), datasets in the workspace can be used by all members with dataset use permissions by default.

      For example, you can use the dataset to create reports like ad hoc queries, dashboards, and workbooks.

    • If you select specified members, unauthorized users cannot use datasets in the workspace by default.

      To grant use permissions on a dataset, see Grant use permissions on a dataset.

  • Edit data sources: You can set the default to either All workspace members (for members with data source edit permission) or private.

    This setting determines the default Edit permission in the collaborative authorization panel for new data sources.

    • If the default is private, the edit permission defaults to private, meaning unauthorized users cannot edit the data source.

    • If the default is All workspace members (for members with data source edit permission), the edit permission defaults to All workspace members (for members with data source edit permission), meaning members with data source editing permissions can edit the data source.

    image.png

    • If you select All workspace members (for members with data source edit permission), data sources in the workspace can be edited by members with data source editing permissions by default.

      ① Replace the data source.

      ② Modify the data source.

      image.png

    • If you select private, unauthorized users cannot edit data sources in the workspace by default.

      To grant edit permissions on a data source, see Grant permissions on a data source.

  • Use data sources: You can set the default to either All workspace members (for members with data source use permission) or specified members.

    This setting determines the default use permission in the collaborative authorization panel for new data sources.

    • If the default is specified members, the use permission defaults to specified members, meaning only specified members can use the data source.

    • If the default is All workspace members (for members with data source use permission), the use permission defaults to All workspace members (for members with data source use permission), meaning members with data source use permissions can use the data source.

    image.png

    • If you select All workspace members (for members with data source use permission), data sources in the workspace can be used by members with data source use permissions by default.

      Using a data source allows you to perform the following actions:

      ① Create a dataset.

      ② Start a data preparation.

      ③ View table details.

      image.png

    • If you select specified members, unauthorized users cannot use data sources in the workspace by default.

      To grant use permissions on a data source, see Grant permissions on a data source.