Instance Security
Instance security is disabled by default. Once enabled, it is turned on at an object level, and the following object types can each independently have security applied to them:
- Models
- Cubes
- Workviews
- Cards
- Dimensions
- Dimension Elements
- Processes
- Schedules
- Tables
- Applications
- Mappings
- Variables
Once security is enabled for an object type, users have no access to it by default, until access is explicitly granted. Access is granted at one of three levels: Read, Write, or No Access.
Security is applied via Groups: rather than setting permissions per user, permissions are set on a group, and users are then added to that group to inherit its access.
Most commonly, security is applied to dimensions. For example, restricting access to an Employee dimension so only select users can access it, or restricting individual elements within a dimension so managers can only see their own employees' or department's data.
Related entries: MODLR Security, Access Tags and Application Security, userSecurity, userSecurity.groups, Group, userSecurity.users