Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 4 additions & 4 deletions data-apps.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -201,9 +201,9 @@ Data apps also power reusable custom chart types, which are built and managed in

## Sharing an app

Newly created apps are personal - only you can see them. Apps will initially appear in **Settings \> My apps.** To share an app with your team, add it to a space.
Newly created apps are personal - only you can see them. Apps will initially appear in **Settings \> My apps.** To share an app with your team, add it to a space or use [Direct access](/workspace-admin/direct-access).

Access to a data app is controlled by two things working together: the user's **project role** and their **space access level**.
Access to a data app combines the user's **project role** with their **space access** or [direct content role](/workspace-admin/direct-access#how-roles-combine).

### Project role

Expand All @@ -212,7 +212,7 @@ Your [project role](/workspace-admin/roles#project-roles-and-permissions) determ
| Project role | What they can do with data apps |
| :-------------------- | :--------------------------------------------------------------------------------------------------------------- |
| **Viewer** | Cannot open data apps. A data app runs new queries on the fly, which Viewers don't have permission to do. |
| **Interactive Viewer** | Open and interact with shared data apps (in spaces they can access). Cannot create new apps or edit existing ones. |
| **Interactive Viewer** | Open and interact with shared data apps (through space access or direct access). Cannot create new apps or edit existing ones. |
| **Editor** | Everything an Interactive Viewer can do, plus create new apps and edit/rename/move/delete apps in spaces they can edit. |
| **Developer** | Same as Editor for data apps. |
| **Admin** | Same as Editor for data apps, plus access to every space in the project (admins inherit `Full access` to all spaces). |
Expand All @@ -229,7 +229,7 @@ Once an app is added to a space, the user's [space access level](/workspace-admi
- Users with `Can edit` or `Full access` to the space can iterate on it, rename it, move it, and delete it (if their project role allows editing).
- The app respects the same project-level access controls (user attributes, row-level filters) as the rest of your content.

Personal apps stay tied to whoever created them until they're moved into a space. Once moved, the original creator no longer has special rights - access is governed entirely by the space.
Personal apps stay tied to whoever created them until they're moved into a space. Once moved, the original creator no longer has special rights - access follows its space and any direct assignments.

<Frame>
![Clean Shot 2026 04 29 At 18 39 56@2x](/images/CleanShot-2026-04-29-at-18.39.56@2x.png)
Expand Down
1 change: 1 addition & 0 deletions docs.json
Original file line number Diff line number Diff line change
Expand Up @@ -329,6 +329,7 @@
"group": "Access and permissions",
"pages": [
"workspace-admin/roles",
"workspace-admin/direct-access",
"workspace-admin/custom-roles",
"workspace-admin/manage-groups",
"workspace-admin/user-attributes",
Expand Down
2 changes: 1 addition & 1 deletion explore/dashboards.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -296,4 +296,4 @@ The tile now displays without its header. Repeat the steps and click the eye ico

## Share your dashboard

Copy the URL, or press the 🔗 button, to share the dashboard with other people in your organization. To share it with a particular set of filter values applied, see [sharing a dashboard with filter overrides](/explore/dashboards/filter#sharing-a-dashboard-with-filter-overrides).
Copy the URL, or press the 🔗 button, to send the dashboard to people who already have access. To grant users or groups access to this dashboard, use [Direct access](/workspace-admin/direct-access), including its rules for dashboard-owned and reusable charts. To share it with a particular set of filter values applied, see [sharing a dashboard with filter overrides](/explore/dashboards/filter#sharing-a-dashboard-with-filter-overrides).
2 changes: 2 additions & 0 deletions explore/search.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -27,6 +27,8 @@ Results are organized into groups by content type, and items within each group a
<img src="/images/explore/search/search-groups-97b3814af60e64fc7ebc19b97fdfe65c.gif" alt="Search results grouped by content type" />
</Frame>

Content shared directly with you is also discoverable through [Shared with me](/workspace-admin/direct-access#find-shared-content).

## Browsing instead of searching

When you don't know what you're looking for yet, browse. Your home page lists recent and pinned content as soon as you land in Lightdash.
Expand Down
2 changes: 1 addition & 1 deletion explore/share-charts.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ Create a new saved chart, or update an existing one, with the **Save chart** but
<img src="/images/explore/share-charts/save-chart.png" alt="The Save chart button on the chart panel" />
</Frame>

Everyone in your project can reach a saved chart, as long as they have access to the space you saved it to. They can find it under **Browse → All saved charts**, or you can send them the URL directly.
Users with access to the containing space can find the chart under **Browse → All saved charts**, or you can send them its URL. To share an individual saved chart without sharing its space, use [Direct access](/workspace-admin/direct-access). That guide also explains how sharing differs for dashboard-owned and reusable charts.

<Frame>
<img src="/images/explore/share-charts/saved-charts-browse.png" alt="Browsing all saved charts" />
Expand Down
2 changes: 1 addition & 1 deletion explore/spaces.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -89,7 +89,7 @@ For what each space role can do, see [the space roles table](/workspace-admin/ro

**Only admins and members that are invited to a Space with Restricted Access have access to it.**

For example, here I have a Space with Restricted Access. Only admins and the invited members have access to this Space. Katie, Filipe and Marshall have inherited `Full Access` because they are organization admins. Priyanka was invited to the space, so she has `Can View` access to the space. No one else in Lightdash can see or interact with the content in this Space unless they're invited or become an admin.
For example, here I have a Space with Restricted Access. Only admins and the invited members have access to this Space. Katie, Filipe and Marshall have inherited `Full Access` because they are organization admins. Priyanka was invited to the space, so she has `Can View` access to the space. Individual items can also be shared through [Direct access](/workspace-admin/direct-access), which does not grant access to browse this Space.

Only users with `Full Access` permissions to a Restricted Access Space can invite other users to that Space.

Expand Down
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
24 changes: 24 additions & 0 deletions workflow/content-as-code.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -1164,3 +1164,27 @@ See [Editing dashboards with agents](/workflow/edit-dashboards-with-agents) for
## Validate content YAML in your editor

Set up JSON schema validation in your editor so chart and dashboard YAML is checked — with autocomplete and inline errors — as you write it. See [Set up VS Code](/workflow/set-up-vs-code) for the schema configuration.

## Direct access to content

Dashboards, independently saved Explore and SQL charts, and data-app manifests support an optional `access` block for [direct sharing](/workspace-admin/direct-access). Dashboard-owned charts use their dashboard's policy. The block contains stored direct assignments, not inherited roles or expanded group membership.

```yaml
access:
users:
- email: analyst@example.com
role: viewer
groups:
- name: Finance
role: editor
```

Both `users` and `groups` are required arrays when `access` is present. Users are identified by primary email, groups by exact case-sensitive name, and roles are `viewer`, `editor`, or `admin`. Principals must resolve to eligible members or groups in the destination; an upload does not create project membership.

- Omitting `access` preserves the destination item's direct policy.
- Including `access` replaces its entire direct policy, rather than merging assignments.
- Setting both arrays to `[]` removes all direct assignments while retaining inherited access.

Downloads omit the block when there are no direct assignments. If a policy contains an identity that cannot be represented safely by email or group name, the whole block is omitted. Review the downloaded policy before using files to manage permissions.

Applying a policy requires direct access to be enabled and permission to manage the destination item's sharing. Invalid roles, duplicate principals, and unresolved identities are rejected. A content-as-code permission alone does not authorize changing an item's access.
138 changes: 138 additions & 0 deletions workspace-admin/direct-access.mdx
Original file line number Diff line number Diff line change
@@ -0,0 +1,138 @@
---
title: "Direct access"
description: "Share individual dashboards, charts, and data apps with project members"
---

<Info>
<Badge icon="building-plus" color="blue" size="sm" shape="pill">Enterprise</Badge> Direct access must be enabled for your organization. Recipients must be active members of the organization with access to the project.
</Info>

Direct access lets you share individual content with users or groups without sharing its containing space. Use it when someone needs one dashboard, chart, or data app from a restricted space.

This page covers [sharing and revoking access](#manage-direct-access), [roles](#how-roles-combine), [content boundaries](#what-a-grant-covers), [discovery](#find-shared-content), and [access after content or membership changes](#content-and-membership-changes). For automation, see the [access API](#access-api) and [content-as-code](/workflow/content-as-code#direct-access-to-content).

## Manage direct access

You need effective **Full access** to the content to manage its direct assignments. This can come from an organization, project, space, or direct content role. A personal data app's creator can also manage its sharing. **Can edit** alone does not let you manage sharing.

1. Open the dashboard, independently saved chart, saved SQL chart, or data app and select **Share**. On a dashboard, open the three-dot menu (`…`) to find it.
2. In **Share with**, select a user or group. Users must already have project access; groups must have access to the project.
3. Choose **Can view**, **Can edit**, or **Full access**, then click **Share**.
4. Send the recipient the content's URL, or direct them to **Shared with me**.

<Frame caption="A user with direct Can view access to Revenue overview">
<img src="/images/workspace-admin/direct-access/share-user.png" alt="Share dialog listing Viewer User with Can view access to Revenue overview" />
</Frame>

To share with a group, select it in **Share with** and click **Share** with the appropriate role.

<Frame caption="Selecting a project group to share with">
<img src="/images/workspace-admin/direct-access/share-group.png" alt="Finance reporting selected in Share with, with Can view chosen and the Share button enabled" />
</Frame>

### Change a role

To change an assignment, choose another role beside the user or group. Changes are saved as you make them; **Done** closes the dialog.

<Frame>
<img src="/images/workspace-admin/direct-access/change-role.png" alt="Role dropdown beside Viewer User offering Can view, Can edit, and Full access" />
</Frame>

### Revoke access

To revoke one assignment, click its **Remove access** trash icon. **Remove all access** removes all direct assignments on this item. Removing your own assignment or all assignments asks for confirmation because you may lose access yourself.

<Frame>
<img src="/images/workspace-admin/direct-access/remove-access.png" alt="Remove all access confirmation explaining that access through spaces remains, with Cancel and Remove buttons" />
</Frame>

<Note>
The Share dialog lists direct assignments, not everyone who can access the content. Removing an assignment leaves any access the recipient has through another user, group, space, project, or organization role.
</Note>

## How roles combine

Direct roles add access to one item. They do not reduce permissions from another source or change the user's project role.

| Direct role | Content access |
| --- | --- |
| **Can view** | View and interact with the item, subject to the user's project permissions. |
| **Can edit** | View and edit the item, subject to the user's project permissions. |
| **Full access** | Edit the item and manage its direct assignments, subject to the user's project permissions. |

Lightdash combines applicable inherited access, direct user assignments, and direct group assignments. The highest applicable content role wins. For example, a user with **Can view** directly and **Can edit** through a group can edit. Removing the user assignment does not remove their group access.

A content role does not supply missing project capabilities. For example, granting **Can edit** to a project Viewer does not give them access to the Explore view. Custom roles, data permissions, user attributes, and row-level filters still apply. See [roles and permissions](/workspace-admin/roles) for project capabilities.

## What a grant covers

| Content | Boundary |
| --- | --- |
| Dashboard | The dashboard and charts saved directly to that dashboard. Manage those charts' access through the dashboard. |
| Independently saved Explore chart | That chart, without granting access to its containing space or other charts. |
| Independently saved SQL chart | That SQL chart. SQL charts owned by a dashboard follow the dashboard's access. |
| Personal or space-backed data app | That app. Queries still run with the viewer's permissions; linked content retains its own checks. |

For example, a **Revenue overview** dashboard in a restricted **Finance** space contains an owned revenue chart and a reusable **Customer detail** chart saved separately. Sharing the dashboard lets the recipient view the dashboard and its owned chart. They still need separate access to **Customer detail**. They cannot browse Finance or open its other dashboards through this grant.

A dashboard grant does not grant access to independent saved charts, saved SQL charts, data apps, or external connections referenced by its tiles. Share independent content separately and check its prerequisites. Direct access also does not expand the data a user can query.

## Find shared content

Open the project's spaces page and select **Shared with me** to find content shared directly with you or one of your groups. You can also open a direct URL. Search includes directly accessible content among its supported result types; it does not make unrelated content in a restricted space accessible.

<Frame caption="Shared with me for a member who cannot browse the containing space">
<img src="/images/workspace-admin/direct-access/shared-with-me.png" alt="Shared with me tab listing the Revenue overview dashboard for a recipient with a direct group grant" />
</Frame>

The containing space remains restricted. A direct grant does not let you browse that space, change its settings, or discover its sibling content. Use the shared item itself as your entry point.

## Content and membership changes

| Change | Effect on access |
| --- | --- |
| Move an item | Direct assignments stay with the item. Its inherited access follows its destination. Moving space-backed content requires the relevant source and destination space permissions; a direct grant alone does not supply them. |
| Duplicate an item | The copy is separate content. Review and configure its sharing; direct assignments on the source are not a sharing policy for the copy. Copying content out of a dashboard can require source-space access. |
| Promote content | Check permissions in the destination project and review the destination item's sharing. A grant in the source project does not confer access to the destination project. |
| Soft delete and restore | Deleted content is unavailable. Where restore is supported, stored assignments can apply again after restoration, subject to current membership and access checks. |
| Permanently delete | The item's direct assignments are removed with it. |
| Change group membership | Group access applies only while the user belongs to the group and the group has project access. Other applicable assignments can still provide access. |
| Remove project access or deactivate a user | Stored direct assignments do not bypass the requirement for active organization and project membership. |
| Revoke an assignment | That assignment stops granting access. Other applicable assignments and inherited roles continue to apply. |

For exports and scheduled deliveries, the user's permissions and access to the originating content still apply. A direct role does not grant unrestricted exporting, scheduling, or access to delivery integrations.

## Direct access, public links, and embedding

Direct access is authenticated sharing with existing project members. Copying a URL does not invite someone to the project or make content public.

[Public dashboard links](/explore/dashboards#share-your-dashboard) and [embedding](/embed) use separate access controls. Direct user or group assignments do not authorize an embed JWT; configure embedded access through the embedding settings and token contract.

## Access API

The project-scoped v2 API manages the same direct assignments as the Share dialog. It requires permission to manage direct access on the target item, including when listing assignments.

The base path is:

```text
/api/v2/projects/{projectUuid}/direct-access/{resourceType}/{resourceUuid}/assignments
```

Use `dashboard`, `chart`, `sqlChart`, or `app` for `resourceType`.

| Request | Operation |
| --- | --- |
| `GET` base path | List stored direct assignments. Inherited and effective roles are not included. |
| `PUT` base path + `/{principalType}/{principalUuid}` | Create or replace one assignment with a JSON body such as `{"role":"viewer"}`. |
| `DELETE` base path + `/{principalType}/{principalUuid}` | Revoke one assignment. An absent assignment is a successful no-op. |
| `DELETE` base path | Remove all direct assignments for the item. |

`principalType` is `user` or `group`; `principalUuid` identifies an existing eligible user or group. API roles are `viewer`, `editor`, and `admin`, corresponding to the three roles above. Requests do not create project membership.

## Troubleshoot access

If someone cannot open shared content, check that direct access is available, their account is active, and they still have project access. For a group assignment, check both their group membership and the group's project access. For a failed tile or linked query, check the independent dependency's access too.

If someone can view but cannot edit, export, schedule, or move content, check their project capabilities and any source or destination space requirements. **Full access** to an item does not make them a project or space administrator.

If someone still has access after you remove an assignment, check their other groups and inherited permissions. Direct access is additive; removing one path does not remove the others.
Loading
Loading