Skip to content

Configure roles and data sources

This guide is for permission administrators. Apply the principle of least required access.

Owner does not mean reader

An owner can modify content. To grant read access:

  • use an existing role when it already represents the group;
  • create a limited role when access must be exclusive;
  • do not make someone an owner just so they can view.
Dashboard properties with owners and roles
Owners maintain content; roles determine who can access it.

Add the exact source to the role

  1. Open Security → List roles.
  2. Edit the role receiving access.
  3. Search for datasource access under Permissions.
  4. Choose sources used by the dashboard, for example:
    • robotic.sensor_data
    • robotic.sensor_stops
    • robotic.sensor_stops_daily_sensor
  5. Save.
  6. Ask the person to sign out and in if the change does not appear.

Zero, one, or several roles

  • Zero explicit roles: normal security rules apply, and data sources still need permission.
  • One role: access is limited to that group.
  • Several roles: membership in any one is enough; they work like an “OR” condition.

Checklist

  • The content has a real owner.
  • The recipient belongs to an allowed role.
  • The role has datasource access for every source.
  • all datasource access was not granted without a documented reason.
  • The test used the recipient’s account.