Qubit Docs العربية

Access Control

Workspace roles decide what people can do. Access control decides which data they can query. It has three parts, each with its own tab under Security & access in the workspace settings:

  • Member groups collect members so you can give them the same access.
  • Data permissions decide which connections, schemas, and tables members can query.
  • Row restrictions decide which records appear inside those tables.

Qubit applies data permissions and row restrictions to every query, including dashboard widgets and the queries the Assistant runs for you.

Member groups

A group collects members so you can assign the same data permissions to all of them. A group grants no access by itself.

  1. Open Member groups and click Create group.
  2. Enter a name and, if you like, a description, then click Create.
  3. Click Add members on the group, choose the members, and click Add.

When someone changes teams, move them to another group and their access follows. Deleting a group keeps its members in the workspace.

Data permissions

A data permission opens selected data to the members and groups you assign to it.

Owners and admins can always use every connection. Until the first data permission exists, members can also use every connection. Creating the first data permission turns enforcement on: from then on, members without an assigned permission lose access to every connection. Deleting the last data permission turns enforcement off again.

To create one:

  1. Open Data permissions and click Create data permission.
  2. Name the permission.
  3. Under Who gets this permission, add members or groups.
  4. Under What they can query, add one or more data scopes:
    • All connections: every connection in the workspace, including ones added later.
    • Connection: every table on the connections you select.
    • Schema: every table in the schemas you select.
    • Table: only the tables you select.
  5. Click Create permission.

Row restrictions

A row restriction limits the records returned from a table that someone can already query. It never grants access. Row restrictions apply to every role, including owners and admins.

  1. Open Row restrictions and click Create row restriction.
  2. Give it a Restriction name.
  3. What it filters: pick the connection, then the table, or choose Every table on this connection.
  4. Who it applies to: choose a Filter type:
    • Regular: the filter runs only for the members, groups, data permissions, or workspace roles you list.
    • Base: the filter runs for everyone except those you list.
  5. The filter itself: write the SQL clause that Qubit adds to the query's WHERE clause, for example region = 'North'. Use current_user_email() or current_username() to filter by the person running the query.
  6. Click Create.

The clause is not checked until a query runs, so test it with a member it applies to.

When several restrictions apply to the same table, the Group key (optional) field controls how they combine. To see it, open Optional: combine with other filters in the dialog. Restrictions with the same key combine with OR. Restrictions with different keys combine with AND. Leave it blank unless you are combining filters.

Example

A sales table has a region column. You create two regular restrictions:

  • region = 'North', listing the North team group.
  • region = 'South', listing the South team group.

Both teams can open the same dashboard. The North team sees only northern sales, and the South team sees only southern sales.

Review a member's access

To check what one person can see, open the Members tab and click View access on their row. Their profile shows their role, groups, data permissions, and the row restrictions that apply to them.