Docs: Sync latest master docs with 7.5.x (#33156)
* Docs: Sync latest master docs with 7.5.x * remove some remaining next aliases and links * Docs: Removed v8 doc changes * fixed merge issue
This commit is contained in:
@@ -41,7 +41,7 @@ Users can belong to one or more organizations. A user's organization membership
|
||||
|
||||
## Dashboard and folder permissions
|
||||
|
||||
Dashboard and folder permissions allow you to remove the default role based permissions for Editors and Viewers and assign permissions to specific users and teams. Learn more about [Dashboard and folder permissions]({{< relref "dashboard_folder_permissions.md" >}}).
|
||||
Dashboard and folder permissions allow you to remove the default role based permissions for Editors and Viewers and assign permissions to specific users and teams. Learn more about [Dashboard and folder permissions]({{< relref "dashboard-folder-permissions.md" >}}).
|
||||
|
||||
## Data source permissions
|
||||
|
||||
|
||||
@@ -0,0 +1,50 @@
|
||||
+++
|
||||
title = "Dashboard and folder permissions"
|
||||
description = "Grafana Dashboard and Folder Permissions Guide "
|
||||
keywords = ["grafana", "configuration", "documentation", "dashboard", "folder", "permissions", "teams"]
|
||||
aliases = ["/docs/grafana/latest/permissions/dashboard_folder_permissions/"]
|
||||
weight = 200
|
||||
+++
|
||||
|
||||
# Grant dashboard and folder permissions
|
||||
|
||||
You can assign and remove permissions for organization roles, users, and teams for specific dashboards and dashboard folders.
|
||||
|
||||
This topic explains how to grant permissions to specific folders and dashboards.
|
||||
|
||||
To learn more about denying access to certain Grafana users, refer to [Restricting access]({{< relref "restricting-access.md">}}).
|
||||
|
||||

|
||||
|
||||
## Permission levels
|
||||
|
||||
Grafana has three permission levels that can be assigned. These permissions are separate from [organization roles]({{< relref "organization_roles.md">}}).
|
||||
|
||||
- **Admin -** Can create, edit, or delete dashboards. Can create, edit, and delete folders. Can also change dashboard and folder permissions.
|
||||
- **Edit -** Can create and edit dashboards. _Cannot_ change folder or dashboard permissions, or add, edit, or delete folders.
|
||||
- **View -** Can only view existing dashboards and folders.
|
||||
|
||||
## Grant folder permissions
|
||||
|
||||
Folder permissions apply to the folder and all dashboards contained within it.
|
||||
|
||||
1. In the sidebar, hover your mouse over the **Dashboards** (squares) icon and then click **Manage**.
|
||||
1. Hover your mouse cursor over a folder and then click **Go to folder**.
|
||||
1. Go to the **Permissions** tab, and then click **Add Permission**.
|
||||
1. In **Add Permission For**, select **User**, **Team**, or one of the role options.
|
||||
1. In the second box, select the user or team to add permission for. Skip this step if you selected a role option in the previous step.
|
||||
1. In the third box, select the permission you want to add.
|
||||
1. Click **Save**.
|
||||
|
||||
## Grant dashboard permissions
|
||||
|
||||
1. In the top right corner of your dashboard, click the cog icon to go to **Dashboard settings**.
|
||||
1. Go to the **Permissions** tab, and then click **Add Permission**.
|
||||
1. In **Add Permission For**, select **User**, **Team**, or one of the role options.
|
||||
1. In the second box, select the user or team to add permission for. Skip this step if you selected a role option in the previous step.
|
||||
1. In the third box, select the permission you want to add.
|
||||
1. Click **Save**.
|
||||
|
||||
## Edit permissions
|
||||
|
||||
To change existing permissions, navigate to the permissions page as described above. Instead of clicking **Add permission**, change or delete permissions already assigned. Changes take effect immediately.
|
||||
@@ -15,7 +15,26 @@ Each organization can have one or more data sources.
|
||||
|
||||
All dashboards are owned by a particular organization.
|
||||
|
||||
> **Note:** Most metric databases do not provide per-user series authentication. This means that organization data sources and dashboards are available to all users in a particular organization.
|
||||
> **Note:** Most metric databases do not provide per-user series authentication. This means that organization data sources and dashboards are available to all users in a particular organization.
|
||||
|
||||
## Compare roles
|
||||
|
||||
The table below compares what each role can do. Read the sections below for more detailed explanations.
|
||||
|
||||
| | Admin | Editor | Viewer |
|
||||
|:---|:--:|:--:|:--:|
|
||||
| View dashboards | x | x | x |
|
||||
| Add, edit, delete dashboards | x | x | |
|
||||
| Add, edit, delete folders | x | x | |
|
||||
| View playlists | x | x | x |
|
||||
| Create, update, delete playlists | x | x | |
|
||||
| Access Explore | x | x | |
|
||||
| Add, edit, delete data sources | x | | |
|
||||
| Add and edit users | x | | |
|
||||
| Add and edit teams | x | | |
|
||||
| Change organizations settings | x | | |
|
||||
| Change team settings | x | | |
|
||||
| Configure app plugins | x | | |
|
||||
|
||||
## Organization admin role
|
||||
|
||||
@@ -23,13 +42,14 @@ Can do everything scoped to the organization. For example:
|
||||
|
||||
- Can add, edit, and delete data sources.
|
||||
- Can add and edit users and teams in their organization.
|
||||
- Can add, edit, and delete folders containing dashboards for data sources associated with their organization.
|
||||
- Can add, edit, and delete folders containing dashboards for data sources associated with their organization. They can also edit folder permissions.
|
||||
- Can configure app plugins and organization settings.
|
||||
- Can do everything allowed by the Editor role.
|
||||
|
||||
## Editor role
|
||||
|
||||
- Can view, add, and edit dashboards, panels, and alert rules in dashboards they have access to. This can be disabled on specific folders and dashboards.
|
||||
- Can add, edit, and delete folders containing dashboards for data sources associated with their organization. They cannot edit folder permissions.
|
||||
- Can create, update, or delete playlists.
|
||||
- Can access Explore.
|
||||
- Can add, edit, or delete alert notification channels.
|
||||
|
||||
@@ -0,0 +1,41 @@
|
||||
+++
|
||||
title = "Restricting access"
|
||||
weight = 500
|
||||
+++
|
||||
|
||||
# Restricting access
|
||||
|
||||
The highest permission always wins so if you for example want to hide a folder or dashboard from others you need to remove the **Organization Role** based permission from the Access Control List (ACL).
|
||||
|
||||
- You cannot override permissions for users with the Organization Admin role. Admins always have access to everything.
|
||||
- A more specific permission with a lower permission level will not have any effect if a more general rule exists with higher permission level. You need to remove or lower the permission level of the more general rule.
|
||||
|
||||
Here are some examples of how Grafana resolves multiple permissions.
|
||||
|
||||
## Example 1 (user1 has the Editor Role)
|
||||
|
||||
Permissions for a dashboard:
|
||||
|
||||
- Everyone with Editor role can edit
|
||||
- user1 can view
|
||||
|
||||
Result: `user1` has Edit permission as the highest permission always wins.
|
||||
|
||||
## Example 2 (user1 has the Viewer Role and is a member of team1)
|
||||
|
||||
Permissions for a dashboard:
|
||||
|
||||
- Everyone with Viewer role can view
|
||||
- user1 Can Edit
|
||||
- team1 Can Admin
|
||||
|
||||
Result: `user1` has Admin permission as the highest permission always wins.
|
||||
|
||||
## Example 3
|
||||
|
||||
Permissions for a dashboard:
|
||||
|
||||
- user1 can admin (inherited from parent folder)
|
||||
- user1 can edit
|
||||
|
||||
Result: You cannot override to a lower permission. `user1` has Admin permission as the highest permission always wins.
|
||||
Reference in New Issue
Block a user