Horizon uses three layers of access control that work together to determine what a user can see and do:
- Product access controls which Horizon features your organisation can use.
- User roles control what an individual user can do within Horizon.
- Dashboard permissions control what a user can do with a specific dashboard or workspace.
All Vista Cloud customers receive read-only access to Horizon by default, which allows users to view starter dashboards. Organisations with full access can also create and manage dashboards, reports, and other Horizon content.
A user's effective access is determined by all three layers. Dashboard permissions cannot grant access beyond a user's Horizon role, and user roles cannot provide features that are unavailable under the organisation's product access level. For example, a Basic user can be given Viewer permission to a dashboard, but they cannot edit it because editing requires a Designer or Admin role.
Product access
Horizon is available with either read-only access or full access.
| Product access | Available features |
|---|---|
| Read-only | View starter dashboards only |
| Full access | View starter dashboards, create dashboards, edit dashboards, create reports, perform pivot-table analysis, and integrate with tools such as Power BI and Tableau |
All Vista Cloud customers receive read-only access by default. Contact Vista Support to upgrade to full access.
User roles
A user's role determines what they can access and manage within Horizon.
| Role | Product access required | Access |
|---|---|---|
| Basic | Read-only or Full | View data for assigned sites only |
| All sites | Read-only | View data for all sites in the organisation |
| Designer | Full | Create and modify dashboards and other objects |
| Admin | Full | Full access to all objects and permissions |
For read-only customers:
- Basic users can view starter dashboards for their assigned sites.
- All sites users can view starter dashboards for all sites in the organisation.
For full-access customers:
- Basic users can view dashboards shared with them.
- Designers can create and edit dashboards.
- Admins have full administrative permissions.
Dashboard permissions
Dashboard permissions control access to individual dashboards and workspaces.
| Permission | Compatible user roles | Access |
|---|---|---|
| Owner | Admin, Designer | View, edit, share permissions, rename, transfer ownership, delete |
| Editor | Admin, Designer | View, edit, share permissions |
| Viewer | Admin, Designer, Basic | View only |
| Public | All Horizon users | Visible to all users |
Dashboard permissions are only available to organisations with full access.
How access is evaluated
When a user opens a dashboard, Horizon evaluates access in this order:
- Does the organisation have the required product access?
- Does the user have a Horizon role that supports the activity?
- Does the user have permission to the specific dashboard?
For example:
- A Basic user in a read-only organisation can view starter dashboards but cannot access shared custom dashboards because custom dashboards require full access.
- A Basic user in a full-access organisation can view a custom dashboard if they have Viewer permission.
- A Designer can be assigned Editor or Owner permissions because they can modify dashboards.
- An Admin can access and manage all dashboards regardless of ownership.
See also:
Comments
0 comments
Please sign in to leave a comment.