Visualization Permissions

Beta Feature

Visualization Permissions is a beta feature. Its behavior and available settings may change in future releases. Do not use it in a production environment.

Visualization permissions let you restrict access to individual saved visualizations. A restricted visualization is hidden from unauthorized users and shows as unavailable on every dashboard where it appears.

Restricted visualizations are hidden from unauthorized users in the Catalog and the Analytical Designer picker. If a visualization depends on a restricted metric, fact, attribute, or attribute label, GoodData blocks that visualization as well. This prevents sensitive data from being exposed indirectly through a chart.

Saving a visualization and accessing one that already exists are separate permissions. Workspace.CREATE_VISUALIZATION controls the save. The visibility and grants below control access after the visualization exists.

Visualization Creation

Workspace.CREATE_VISUALIZATION is included in Workspace.ANALYZE and Workspace.MANAGE. It is not included in Workspace.VIEW. You can assign it on top of VIEW. Existing ANALYZE and MANAGE assignments keep the ability to save visualizations.

The permission gates saving a visualization. It does not open standalone Analytical Designer or the Catalog, and it does not control who can build and read a chart that is never saved.

  • ANALYZE or MANAGE — users can save visualizations from Analytical Designer and the Catalog, as they can today.
  • VIEW + CREATE_VISUALIZATION — users who have EDIT on a dashboard can save a new visualization from Analytical Designer embedded in dashboard edit mode. They can also save a visualization through the API or Python SDK.

Assign CREATE_VISUALIZATION from Users & groups on the home page, or through the workspace permissions API. You can assign it to users or organization-level user groups. See Manage Workspace Permissions.

Without CREATE_VISUALIZATION, saving a visualization is unavailable in the user interface (the action is hidden or disabled). The API and Python SDK return 403 Forbidden.

Building and reading a chart that is never saved does not require this permission. The AI Assistant can still render a chart in the conversation without saving it.

If the visualization definition references a metric, fact, attribute, or attribute label the caller cannot access, the request is rejected with 404 Not Found, the same as an unknown identifier. The error does not name the restricted object.

Updating or deleting an existing visualization uses the EDIT grant described below.

Visibility and Grants

Visualization permissions are controlled by access settings on saved visualizations.

Visibility States

Visualization permissions support two visibility states:

  • RESTRICTED - only selected users and groups can access the visualization.
  • WORKSPACE - all workspace members have implicit read access.

Newly created visualizations are restricted by default. The creator automatically receives the EDIT grant, so they can continue working with the visualization immediately after creating it.

Backwards Compatibility

Existing visualizations keep All workspace members access, so current dashboards continue to work. Only visualizations created after you enable the feature default to RESTRICTED. You can change visibility at any time.

WORKSPACE visibility grants read access only (implicit VIEW). To share, edit, or delete the visualization, a user needs an explicit grant that allows them to do so.

If you switch a visualization from All workspace members to Restricted, access is removed for workspace members who do not have another access path. Existing individual and group grants are preserved. If you later switch the visualization back to All workspace members, all workspace members can view it again.

A visualization grant does not grant access to the metrics or columns the visualization uses. When sharing a visualization, check that the intended users can also access those objects.

Grants and Access Levels

For restricted visualizations, you can grant access to selected users or organization-level user groups.

Supported access levels are:

  • VIEW — can see and use the visualization.
  • SHARE — can use the visualization and share it with others.
  • EDIT — full control over the visualization, including updating and deleting it. EDIT includes everything SHARE provides.

When a new visualization is created, the creator automatically receives the EDIT grant. A visualization cannot be left without an EDIT grant. Grant EDIT to another user or organization-level user group before removing the last one.

You can also remove shared access. If the user or group still has access through another path, such as a user group or workspace-wide access, GoodData indicates that access remains.

Workspace-level user groups are not supported.

Behavior and Enforcement

Restricted visualizations are hidden from unauthorized users. Users without access do not see them in the Catalog or the Analytical Designer picker.

Direct access to a restricted visualization returns 404 Not Found so the existence of the visualization is not exposed. GoodData does not return 403 Forbidden for a restricted visualization, because that would reveal that the visualization exists.

A dashboard that contains a restricted visualization still opens for users who can access the dashboard. The visualization shows as unavailable in its place, and the rest of the dashboard renders. The visualization’s access policy applies on every dashboard that uses it.

Visualization permissions are also enforced across dependencies. If a user does not have access to a metric, fact, attribute, or attribute label used by the visualization:

  • the visualization is blocked, even when it is visible to all workspace members or the user has an explicit grant on it
  • GoodData does not omit the inaccessible series, filter, or sort and render the rest of the chart

See Metric Permissions and Column-Level Permissions. Dashboard access is separate. See Manage Dashboard Permissions.

The same access rules are enforced in the API and Python SDK.

API list endpoints omit restricted visualizations for unauthorized users. Direct access to a restricted visualization returns 404 Not Found. A request for a dashboard still returns that dashboard and marks the restricted visualization as unavailable.

SDK calls follow the same rules as the REST API. Catalog calls do not return restricted visualizations to unauthorized users.

Users with Workspace.MANAGE or Organization.MANAGE can see all visualizations regardless of visibility or grants. This admin bypass applies across the UI, catalogs, dashboards, API, and SDKs.

Set Permissions for Visualizations

You manage access from the visualization’s sharing settings. Choose the visualization’s general access:

  • Restricted - only selected users and groups can access the visualization.
  • All workspace members - everyone in the workspace can view the visualization.

To share the visualization with selected users or groups, add them and choose their access level. The selected users or groups then have the access you assigned.