- Dashboard project-level permission
- Chart project-level permission
- Dashboard-level permission
- Chart-level permission
The three permission levels
Both dashboards and charts use the same three levels.
They form a strict hierarchy:
Project-level permission
Project-level permission defines the maximum capability a user can have for a feature. Dashboard and chart project-level permissions are configured independently of each other. A user might hold Full Access for charts and Viewer for dashboards, or any other combination. Each is evaluated on its own.Resource-level permission
Resource-level permission applies to an individual dashboard or an individual chart. A specific resource can be assigned Full Access, Editor, or Viewer.Effective permission
Effective permission is what the user can actually do. It is determined by:- Project-level permission
- Resource-level permission
- Resource visibility and sharing configuration
* The UI can allow a resource owner to assign a permission higher than the recipient’s project-level permission by showing a warning message. The effective permission still resolves down to the project-level ceiling.
Resolution order
Klaritics evaluates permissions in a fixed order, and the same logic is used everywhere access is decided.Action visibility
The actions available on a resource follow directly from the effective permission.- Dashboard
- Chart
Dashboards and charts are independent
Access to a dashboard does not grant equivalent access to the charts inside it. This is the single most important rule in the model. Example A user holdsDashboard 1 = Editor and Chart 1 = No Access.
The user can:
- Open Dashboard 1
- Edit Dashboard 1
- Add existing charts they are allowed to access
- View the content or data of Chart 1
- Edit Chart 1
Further combinations
Creating resources
Only a user with Full Access can create a dashboard or a chart. Editor and Viewer cannot create new resources in the current version; an Editor works with existing dashboards and charts that have been shared with them.Duplicating
Only a user with Full Access can duplicate a dashboard or chart. A duplicate:- Receives a new unique ID
- Uses a default name such as
Dashboard 1 - Copy - Is owned by the user who performed the duplication
- Is Private by default
- Does not inherit the original resource’s sharing permissions
Deleting
Deleting requires confirmation, and the dialog clearly identifies the resource being deleted. On confirmation, the resource is removed from the project.Deleting a dashboard does not delete the charts it contained. Those charts remain available in Saved Charts unless you delete them explicitly.
Enforcement
The UI does not rely only on hiding actions. Every permission-sensitive operation is also validated at the backend and API level, using the same permission model as the frontend. In practice this means:- A Viewer cannot call an edit API directly.
- An Editor cannot call the delete API.
- A user cannot assign a permission higher than allowed.
- A user cannot reach a private resource through a manually constructed URL.
Not supported in the current version
The following are outside the current permission model:- Multiple roles assigned to the same user
- Custom user-defined roles for dashboards and charts
- Role inheritance
- Cross-project permissions
- Organization-level permissions
- Temporary permissions and permission expiry
- Approval workflows for sharing
Next steps
- Share dashboards and charts for Private, Restricted, and Project-wide visibility
- Saved Charts for the chart listing and its actions
- Roles for the organization-level role model