Skip to content

Control Who Can See a Dashboard

Every dashboard has an audience — the people who can open it. A dashboard’s owners and workspace admins choose that audience in PlaidCloud, from one dialog, in terms of security groups. PlaidCloud applies the choice everywhere the dashboard appears: Home, My Dashboards, the dashboard itself, a direct link, thumbnails, PDF exports and the AI assistant.

Audience Who can open the dashboard
Everyone in the project Everyone with access to the dashboard’s projects. This is the default.
Specific groups Members of the groups you choose, plus the dashboard’s owners and workspace admins.
Only owners (Draft) The dashboard’s owners and workspace admins. Groups chosen earlier are kept and regain access when the dashboard is published again.
Unlisted Not listed anywhere, but anyone in the project with the link can open it. This is how an unpublished dashboard starts out.
Custom (Superset roles) Holders of roles set directly in the dashboard service. PlaidCloud shows these read-only.

Owners and workspace admins always see a dashboard, whatever its audience. Workspace admins are the dashboard service’s administrators, so they see every dashboard, including drafts. Badges on Home tiles and in My Dashboards show a dashboard’s audience, and owners see their own drafts and unlisted dashboards with a badge.

  1. Open the dashboard’s Who can see this? action — from its tile on Home, from its row in My Dashboards, or from the Audience column.
  2. Choose Everyone in the project, Specific groups or Only owners (Draft). Each option shows how many people it covers.
  3. For Specific groups, tick the groups. The list holds the groups that have access to the dashboard’s project, with their member counts, and Search groups narrows it.
  4. Read the Impact line — for example, “28 of 42 project members will see this”. See who lists the people who gain access and the people who lose it, and Preview as… shows, for any member you select, whether they can see it and why.
  5. Select Save.

Always included lists the owners and the workspace admins; they can’t be removed. Only a dashboard’s owners and workspace admins can change its audience; everyone else sees the dialog read-only.

Things the dialog tells you:

  • A dashboard that spans several projects lists every group with access to any of them. A group that can’t access one of the projects is flagged — its people won’t see every chart.
  • A dashboard with no charts shows “Add a chart to set who can see this.”
  • A group that has been deleted shows as “Deleted group (0 people)” and loses access when you save. An empty group shows “nobody is in this group yet.”
  • A dashboard with Superset roles shows Custom (Superset roles). Specific groups keeps those roles alongside the groups you choose; Everyone in the project removes them, after you confirm with Remove roles and save.
  • If someone else saves the dashboard while the dialog is open, the dialog reloads and asks you to review and save again.

Group membership changes take effect within about a minute: add someone to a group and they can open the dashboard, remove them and they can’t, without signing out. The dashboard’s properties in the dashboard service show the same audience read-only, with a Manage in PlaidCloud link back to this dialog.

A copy of a dashboard has the same audience as the original, so a copy is never visible to more people than its source. Anyone who can see a dashboard that has no audience restriction can copy it with Save As. A dashboard restricted to groups can be copied only by its owners and workspace admins.

Someone in the project who isn’t in a dashboard’s groups sees a Request access page when they open it, naming the dashboard’s owners. They add an optional note and send the request. Anyone else — without access to any of the dashboard’s projects — sees only that the dashboard doesn’t exist or isn’t available to them.

Each owner and workspace admin gets an email with the requester and their note. Opening it brings up the dashboard’s Who can see this dialog with an Access request panel:

  • Add one of the groups the requester is already in lists the groups that contain the requester. None is ticked for you; choose one and select Save to grant access.
  • Dismiss closes the request without granting anything.

A request closes when the person gains access or someone dismisses it. If the requester belongs to no eligible group, add them to one in Managing Security Groups and Assignments.

Workspace admins open Access Review in the Dashboards toolbar to audit every dashboard at once. Dashboard Access Review lists each dashboard with its audience, groups, number of people, owners, when it last changed and who changed it, and its Data exposure.

Use Show to filter by Restricted, Everyone in the project, Only owners (Draft), Unlisted, Custom (Superset roles), Restricted, but data uncovered — restricted dashboards whose datasets have no row rules — or Owner has left. Select a dashboard to open its audience dialog; Open Row Access goes to the Row Access screen for an uncovered dataset. Download CSV exports the list as it is filtered.

The review covers the projects you can access, and says so when a dashboard also uses projects you can’t.

In My Dashboards, select up to 50 dashboards and choose Set audience…. The dialog offers only the groups that can see every selected dashboard, and its Impact line totals across all of them. When it finishes, Result reports how many dashboards changed, were skipped, failed or were in conflict, with the reason for each skipped one — for example, a dashboard you don’t own, or one with Superset roles when you didn’t choose Remove the Superset roles and save those too.

A project can decide who sees the dashboards built on its data. In the project’s Home tab, Default Dashboard Audience is either Everyone in the project (the default) or Specific groups, with the groups to limit new dashboards to.

The default applies to a dashboard the first time it is published, and never to dashboards that already exist. A dashboard whose audience an owner has chosen — including an explicit Everyone in the project — keeps that choice. A dashboard that spans several projects takes the groups common to all of their defaults; if no group is common to all of them, it starts as a draft for its owners. A project shared with individual members rather than groups has no default audience to set.

The dashboard_audience_manage tool does the same from the AI assistant and the MCP server: it can get a dashboard’s audience, preview a change, set it, and request or dismiss access.