Skip to main content
Version: 8.3.0

Resource Permissions Overview

Overview

What Is a Resource?

In Guandata BI, a resource refers to the various types of analytical content created or uploaded by users, as well as the organizational structures used to manage that content. Examples include Dashboards, Data Screens, Datasets, Dashboard folders, and Dataset folders.

What Are Resource Permissions?

Resource Permissions are used to control which resources a user can view and what operations the user can perform on those visible resources.

By configuring resource permissions properly, administrators can finely control how users access and operate on different resources, improving both data security and collaboration efficiency.

Resource Permission Types

For each resource such as a Dashboard or Dataset, as well as resource folders such as Dashboard folders, the system supports different resource permission types. These permission types determine what operations users can perform on the resource. For detailed behavior, see Resource Permission Details.

Permission TypeDefinitionNotes
OwnerHas full permissions on the resource, for example modifying dashboard or Dataset content, creating or deleting cards, adjusting card layout, and editing fields in cardsIf the user is an administrator, they always have full permissions on the resource, regardless of whether they are the owner or only a viewer
Viewer / User
  • Viewer

    • For page-type resources such as Dashboards and Data Screens, this is view-only permission
    • For folders, users can create pages or Datasets inside the folder

  • User: for Datasets, the user can create cards based on the Dataset but cannot modify the Dataset itself
  • If the user is an administrator, they always have full permissions on the resource, regardless of whether they are the owner or only a viewer
    Exporter
    (not available for folders)
  • Can download Dashboards as images or Excel files
  • Can download data from Datasets
  • Export permissions can be globally controlled in Admin Center > System Settings > General Settings > Export.


  • If export control is not enabled, export permissions are unrestricted, and users can export any page or Dataset they can view. This is not recommended
  • If export control is enabled, all users are unable to export by default, and export permission must be granted explicitly to selected users or user groups. Taking a Dataset as an example:

    1. Assign Dataset export permission in Role Permission Configuration

    2. Assign the user or user group as Exporter for that Dataset

  • Resource Permission Authorization Methods

    This section introduces authorization methods only. For step-by-step operations, see Resource Permission Details.

    Single-Resource Authorization

    Configure permissions directly for users or user groups on a specific resource. This is suitable for personalized and precise permission assignment.

    Configuration entry points

    • Admin Center > Resource Management > Resource Permission Management, then select a resource for authorization
    • Admin Center > Users / User Groups > Permission Information > Resource Permissions
    • Click the Permission Management button on a page, Dataset, or folder

    Batch Authorization Based on Folders

    Batch authorization is an operation for centralized management of scattered data resources. A large number of datasets or dashboard pages are categorized and placed in different folders. Resources within the same folder typically share the same group of authorized users. To make permission management more convenient, we provide folder-based batch authorization.

    • For pages/datasets in the same folder, after a batch authorization list is set on the folder, it takes effect for all resources in the folder.
    • If some pages/datasets have special requirements and need separate control, they can also choose not to inherit the batch authorization list from the parent folder.
    Note
    • The current version only supports batch authorization for dashboards, data screens, and datasets. If you have more related needs, please contact your counterpart for feedback.
    • If you are unsure whether to inherit from the parent, you can choose Follow global, which is controlled by the global Folder batch authorization inherits parent switch.
      • When the switch is enabled: the Follow global option on the page displays as Follow global (inherit parent); if multiple parent folders have inconsistent batch authorizations, the final permissions are merged as a union.
      • When the switch is disabled: the Follow global option on the page displays as Follow global (do not inherit parent).

    Folder permission inheritance rules

    1. Permissions are revoked from the same source they were granted. Therefore, if a user A obtained permissions for the dashboard/data screen/dataset through batch authorization, the corresponding permissions must also be revoked at the batch authorization location, not directly on the page/dataset.
    2. When batch authorizing folders and their resources, you can choose one of three inheritance methods: Follow global, Inherit parent, or Do not inherit parent.
    3. Which permissions a resource such as a page/dataset has is determined jointly by: whether the folder has batch authorization, whether the folder inherits from the parent, and whether the resource itself inherits from the parent. For example: folder F1 Sales Department has a subfolder F2 East China Sales Team, and the subfolder F2 East China Sales Team has a dashboard P3 East China Target Achievement.
    ScenarioF1 SettingF2 SettingF2 Inheritance SettingResource P3 Inheritance SettingResource P3 Permission
    Scenario 1Batch authorization setBatch authorization not set/Inherit parent enabledHas permission, inherited from F1
    Scenario 2Batch authorization setBatch authorization not set/Inherit parent not enabledNo permission
    Scenario 3Batch authorization setBatch authorization setInherit parent enabledInherit parent enabledHas permission, inherited from F2 and F1
    Scenario 4Batch authorization setBatch authorization setInherit parent enabledInherit parent not enabledNo permission
    Scenario 5Batch authorization setBatch authorization setInherit parent not enabledInherit parent enabledHas permission, inherited from F2
    Scenario 6Batch authorization not setBatch authorization setInherit parent enabledInherit parent enabledHas permission, inherited from F2

    Configuration entry points

    • Admin Center > Resource Management > Resource Permission Management, then select a folder for batch authorization
    • Click the Batch Authorization button on a folder

    Resource Permission Authorization Rules

    To standardize resource permission management, the system also provides resource permission authorization rules that control which users can grant permissions and the scope of recipients.

    Entry: Admin Center > User Management > Permission Rules

    Scope of Authorization Recipients

    There are three recipient scope options:

    • Allow authorization to all user groups and users. Regardless of whether this option is selected, administrators can always authorize all users and user groups.
    • Allow authorization only to the current user's own user group, users in that group, child user groups, and users in those child groups. This applies when the current user is a normal member or a group administrator. The visible range in the permission list is limited to the current group, its users, and its child groups.
      If the target exceeds the allowed scope, the platform shows an error.
    • Allow authorization only to the user groups managed by the current user, as well as their users and child groups. This applies when the current user is a group administrator. The visible range in the permission list is limited to the managed groups, their users, and their child groups.
      If the operator is only a normal user, authorization is not allowed.

    Types of Authorization Recipients

    The system can also restrict whether resource permissions may be assigned to user groups. If assignment to user groups is disallowed, you can add exceptions in a whitelist. Users in the whitelist are still allowed to assign permissions to user groups.

    • If assigning permissions to user groups is allowed, user groups can be searched directly on the permission configuration page.
    • If assigning permissions to user groups is not allowed, only individual users can be searched on the permission configuration page.