Who Sees What
A query tool that ignored permissions would be a way to read everything, so BI does not.
Where to find it
Architect Panel → Dashboards:
- Explore — access is granted like any other screen
The permission model still applies
Queries run as the user asking. Someone who cannot see a datastore cannot query it, and row-level restrictions apply to results as they do everywhere else.
Aggregates can still disclose
This is the part worth thinking about. A count of one, broken down finely enough, identifies an individual — a single case in a category in a small area is a person, even though no record was shown. Where you report on small populations, think about minimum group sizes before publishing a breakdown.
Who gets Explore
Explore is powerful and open-ended. Analysts and managers who need to ask their own questions should have it; most people are better served by a dashboard answering the questions they actually have. Giving everyone a query tool tends to produce many slightly different versions of the same number.
Sensitive datastores
Where casework classification and clearance apply, they apply here too. Confirm that with a test account before opening BI up — the reassurance is worth the ten minutes.
Exports leave the building
Anything exported is outside the permission model from that moment. Where that matters, restrict export rather than relying on the query controls alone.