Keep your model clean and your data secure without limiting your team’s access. With custom data access groups, you can grant view or edit rights down to the dimension member level and for a more detailed configuration than our default data access groups.
Build access around how your business operates, from department to region, and ensure every user has the right level of access to work confidently in Cube. For example, limit a team lead's access to data from their own team, regardless of which report or dashboard they are viewing.
- In the User Management page of the Users section, from any tab, click +Create, then click Data Access.
- Enter a unique name for the user type. Then click Next.
-
Each permission row defines the dimensions this role has access to. Configure one or more permissions to ensure this data access group has the necessary permissions. Select the dimension members(s) across the permissions row by checking all or checking specific dimension members from the tree.
If you select a parent, all current and future children are included.
For each permission row, indicate the access level for the selected dimensions:
- View – Users can view data but not edit it
-
Edit – Users can view and update data in the selected dimensions
**To Note: Cube will default to the highest level permissions granted, if multiple permissions are assigned.
Click Add Permission to add rows as necessary.
- (Optional) Add users to this data access group by checking the box next to their name. Add one or more existing users now, or skip this step and assign users later.
Working Example
Each permission row is an intersection of the dimension members selected on that row. A user's visibility is the union of all their rows, across every assigned group.
Example:
A row scoped to Subsidiary A with Departments 1, 2, 3 grants only those departments within Subsidiary A. It does not grant those departments in any other subsidiary.
To give a user Subsidiary A (Dept 1, 2, 3) and Subsidiary B (Dept 3, 4, 5), add two permission rows to a single group, one for each subsidiary/department intersection. A separate group per subsidiary is optional, not required.
Learn how to edit a custom data access group or deactivate a data access group when it’s no longer needed.