<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dashboard Access Policies/Permissions in Dashboarding</title>
    <link>https://community.dynatrace.com/t5/Dashboarding/Dashboard-Access-Policies-Permissions/m-p/295586#M5702</link>
    <description>&lt;P&gt;I have an issue; I am a DT admin and want to view all dashboards created in the tenant. But it looks like until the user explicitly shares it with me, I cannot view it. Is it by design?&amp;nbsp; Because it was not the case with managed.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 03 Mar 2026 22:37:47 GMT</pubDate>
    <dc:creator>SSelvaraj11</dc:creator>
    <dc:date>2026-03-03T22:37:47Z</dc:date>
    <item>
      <title>Dashboard Access Policies/Permissions</title>
      <link>https://community.dynatrace.com/t5/Dashboarding/Dashboard-Access-Policies-Permissions/m-p/271335#M4812</link>
      <description>&lt;P&gt;Hello community,&lt;/P&gt;
&lt;P&gt;The issue I'm facing today is that I'm trying to give a specific user read access to a single dashboard (inside the Dashboards app, so not classic) in my environment. This user should only have this permission, and access to nothing else.&lt;/P&gt;
&lt;P&gt;However I can't seem to be able to figure out a simple/effective way to do it.&lt;/P&gt;
&lt;P&gt;Can anyone give me pointers on how to do this?&lt;/P&gt;
&lt;P&gt;Thanks in advance x)&lt;/P&gt;</description>
      <pubDate>Mon, 03 Mar 2025 10:41:15 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dashboarding/Dashboard-Access-Policies-Permissions/m-p/271335#M4812</guid>
      <dc:creator>PedroSantos</dc:creator>
      <dc:date>2025-03-03T10:41:15Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard Access Policies/Permissions</title>
      <link>https://community.dynatrace.com/t5/Dashboarding/Dashboard-Access-Policies-Permissions/m-p/271366#M4814</link>
      <description>&lt;P&gt;Hello PedroSantos.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Within individual dashboards there is an option to "share" dashboard. There is an opportunity to share access to people and groups that are in your environment with "can view' or "can edit" access. As well as an opportunity to create a link with the same permissions. Please refer to the screenshot below.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="KeeganNelson_0-1740769885022.png" style="width: 400px;"&gt;&lt;img src="https://community.dynatrace.com/t5/image/serverpage/image-id/26755i78AC975A5E6A70AB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="KeeganNelson_0-1740769885022.png" alt="KeeganNelson_0-1740769885022.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Hope this helps!&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 19:11:41 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dashboarding/Dashboard-Access-Policies-Permissions/m-p/271366#M4814</guid>
      <dc:creator>KeeganNelson</dc:creator>
      <dc:date>2025-02-28T19:11:41Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard Access Policies/Permissions</title>
      <link>https://community.dynatrace.com/t5/Dashboarding/Dashboard-Access-Policies-Permissions/m-p/271503#M4815</link>
      <description>&lt;P&gt;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/77112"&gt;@PedroSantos&lt;/a&gt;&amp;nbsp;does it solve your case? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Mar 2025 09:11:19 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dashboarding/Dashboard-Access-Policies-Permissions/m-p/271503#M4815</guid>
      <dc:creator>AgataWlodarczyk</dc:creator>
      <dc:date>2025-03-04T09:11:19Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard Access Policies/Permissions</title>
      <link>https://community.dynatrace.com/t5/Dashboarding/Dashboard-Access-Policies-Permissions/m-p/271633#M4821</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/80335"&gt;@KeeganNelson&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;Unfortunately, this does not solve my problem. The link or share option, &lt;STRONG&gt;by itself&lt;/STRONG&gt;, doesn't grant access to anything.&lt;/P&gt;&lt;P&gt;Case in point, I have a test user with the right "shared" permissions on my dashboard:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PedroSantos_1-1741193316707.png" style="width: 400px;"&gt;&lt;img src="https://community.dynatrace.com/t5/image/serverpage/image-id/26800iCC494663C4D88935/image-size/medium?v=v2&amp;amp;px=400" role="button" title="PedroSantos_1-1741193316707.png" alt="PedroSantos_1-1741193316707.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;(The "Can Edit" option doesn't work either)&lt;/P&gt;&lt;P&gt;And this is what the test user sees:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PedroSantos_2-1741193394398.png" style="width: 400px;"&gt;&lt;img src="https://community.dynatrace.com/t5/image/serverpage/image-id/26801i7D23D4E4262922A0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="PedroSantos_2-1741193394398.png" alt="PedroSantos_2-1741193394398.png" /&gt;&lt;/span&gt; &lt;/P&gt;&lt;P&gt;Generating a link for access provides the following results:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot from 2025-03-05 16-51-54.png" style="width: 400px;"&gt;&lt;img src="https://community.dynatrace.com/t5/image/serverpage/image-id/26802i244DBA35CE3F1A66/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot from 2025-03-05 16-51-54.png" alt="Screenshot from 2025-03-05 16-51-54.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Bluntly put, it's not possible to grant access to a user who doesn't have the permission to, for example, see the dashboards app. In my case the user has permissions to see the dashboards app but something is missing.&lt;/P&gt;&lt;P&gt;In order for a user to be able to see the new dashboards app, and then&amp;nbsp;&lt;STRONG&gt;only&lt;/STRONG&gt; the dashboard I want them to see, they need actual permissions likely defined by policies.&lt;/P&gt;&lt;P&gt;I tried to tweak with the policies and grant access but with this access, comes the ability to see to a lot of pre-set dashboards:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PedroSantos_0-1741192987083.png" style="width: 400px;"&gt;&lt;img src="https://community.dynatrace.com/t5/image/serverpage/image-id/26799i9C127EA44927DBAA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="PedroSantos_0-1741192987083.png" alt="PedroSantos_0-1741192987083.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I don't want them to be able to see any of this.&lt;/P&gt;&lt;P&gt;So my question evolves to:&lt;/P&gt;&lt;P&gt;&lt;U&gt;What permissions and/or policies do I need to define in order to ensure a user only has access to a &lt;STRONG&gt;single&amp;nbsp;&lt;/STRONG&gt;dashboard?&lt;/U&gt;&lt;/P&gt;&lt;P&gt;I understand that at the very least they'll need to have access to the dashboards app so I added this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;ALLOW app-engine:apps:run WHERE shared:app-id = "dynatrace.dashboards";&lt;/LI-CODE&gt;&lt;P&gt;Given there isn't an "easy" way to do this, what else do I need to add?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Mar 2025 17:06:39 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dashboarding/Dashboard-Access-Policies-Permissions/m-p/271633#M4821</guid>
      <dc:creator>PedroSantos</dc:creator>
      <dc:date>2025-03-05T17:06:39Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard Access Policies/Permissions</title>
      <link>https://community.dynatrace.com/t5/Dashboarding/Dashboard-Access-Policies-Permissions/m-p/271637#M4822</link>
      <description>&lt;P&gt;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/77112"&gt;@PedroSantos&lt;/a&gt;&amp;nbsp;Also you can try using custom Policies and Boundaries, where you can defined exactly what you want to share and to whom you want to share:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.dynatrace.com/docs/shortlink/iam" target="_blank"&gt;https://docs.dynatrace.com/docs/shortlink/iam&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Mar 2025 17:13:55 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dashboarding/Dashboard-Access-Policies-Permissions/m-p/271637#M4822</guid>
      <dc:creator>moin_DT1</dc:creator>
      <dc:date>2025-03-05T17:13:55Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard Access Policies/Permissions</title>
      <link>https://community.dynatrace.com/t5/Dashboarding/Dashboard-Access-Policies-Permissions/m-p/272304#M4858</link>
      <description>&lt;P&gt;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/45226"&gt;@AgataWlodarczyk&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Unfortunately, no. It seems it's not possible. As the use-case seems particularly relevant, I have posted a Product Idea: &lt;A href="https://community.dynatrace.com/t5/Product-ideas/Hide-Ready-made-dashboards/idi-p/272303" target="_blank"&gt;https://community.dynatrace.com/t5/Product-ideas/Hide-Ready-made-dashboards/idi-p/272303&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Mar 2025 18:30:06 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dashboarding/Dashboard-Access-Policies-Permissions/m-p/272304#M4858</guid>
      <dc:creator>AntonioSousa</dc:creator>
      <dc:date>2025-03-12T18:30:06Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard Access Policies/Permissions</title>
      <link>https://community.dynatrace.com/t5/Dashboarding/Dashboard-Access-Policies-Permissions/m-p/278263#M5117</link>
      <description>&lt;P&gt;Hye&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/77112"&gt;@PedroSantos&lt;/a&gt;&amp;nbsp;, im new to dynatarce and facing the same issue. have u succeed in creating the policy stated? the initial policy im creating include these permissions:&lt;BR /&gt;\\unified-analysis – for dashboard structure&lt;BR /&gt;ALLOW unified-analysis:screen-definition:read;&lt;BR /&gt;\\Grail&lt;BR /&gt;ALLOW storage:metrics:read;&lt;BR /&gt;ALLOW storage:logs:read;&lt;BR /&gt;ALLOW storage:entities:read;&lt;BR /&gt;ALLOW storage:buckets:read;&lt;BR /&gt;\\slo - ONLY if SLO widgets exist&lt;BR /&gt;ALLOW slo:slos:read;&lt;BR /&gt;&lt;BR /&gt;however w that permissions only, user cant even access the environment, so i add ALLOW environment:roles:viewer to the policy, but now, user have more than just read dashboard access(can edit and create etc). so is there a solution for this? any help would be greatly appreciated&lt;/P&gt;</description>
      <pubDate>Thu, 29 May 2025 03:43:08 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dashboarding/Dashboard-Access-Policies-Permissions/m-p/278263#M5117</guid>
      <dc:creator>Irdina</dc:creator>
      <dc:date>2025-05-29T03:43:08Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard Access Policies/Permissions</title>
      <link>https://community.dynatrace.com/t5/Dashboarding/Dashboard-Access-Policies-Permissions/m-p/278484#M5121</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/88823"&gt;@Irdina&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;What we did was create a policy with the following permissions:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;ALLOW app-engine:apps:run WHERE shared:app-id = "dynatrace.dashboards";
//Grail
ALLOW storage:filter-segments:read, storage:filter-segments:write, storage:filter-segments:delete;
ALLOW storage:system:read;
//Metrics
ALLOW storage:buckets:read WHERE storage:table-name = "metrics";
ALLOW storage:metrics:read WHERE storage:metric.key startsWith "dt.service.request";
ALLOW storage:metrics:read WHERE storage:metric.key startsWith "dt.synthetic.http";
ALLOW storage:metrics:read WHERE storage:metric.key startsWith "dt.synthetic.browser";
//Entities
ALLOW storage:entities:read;
//Documents
ALLOW document:environment-shares:read;
ALLOW state:app-states:read, state:app-states:write, state:app-states:delete, state:user-app-states:read, state:user-app-states:write, state:user-app-states:delete, state-management:app-states:delete, state-management:user-app-states:delete, state-management:user-app-states:delete-all, app-settings:objects:read, app-settings:objects:write;
ALLOW document:documents:read, document:documents:write, document:documents:delete, document:environment-shares:read, document:environment-shares:write, document:environment-shares:claim, document:environment-shares:delete, document:direct-shares:read, document:direct-shares:write, document:direct-shares:delete, document:trash.documents:read, document:trash.documents:restore, document:trash.documents:delete;
ALLOW environment:roles:viewer WHERE environment:management-zone IN ("YOUR-MANAGEMENT-ZONE-NAME");&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;It's not a perfect solution but it's close enough.&lt;/P&gt;&lt;P&gt;We only allow access to the dashboard app. Then we allow access to the metrics bucket, and finally only allow access to specific metrics &lt;STRONG&gt;which are needed to populate this specific dashboard&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;We also limited access to a single, specific, management zone.&lt;/P&gt;&lt;P&gt;That being said, this might not work for your specific dashboard because you need to figure out which metrics your dashboard uses and make a policy for those.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Jun 2025 09:12:54 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dashboarding/Dashboard-Access-Policies-Permissions/m-p/278484#M5121</guid>
      <dc:creator>PedroSantos</dc:creator>
      <dc:date>2025-06-02T09:12:54Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard Access Policies/Permissions</title>
      <link>https://community.dynatrace.com/t5/Dashboarding/Dashboard-Access-Policies-Permissions/m-p/278647#M5129</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/77112"&gt;@PedroSantos&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/60034"&gt;@moin_DT1&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;I have successfully created the intended policy and yes, it is&amp;nbsp;similar to the approach you provided, thank you for the help !!!&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 07:43:43 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dashboarding/Dashboard-Access-Policies-Permissions/m-p/278647#M5129</guid>
      <dc:creator>Irdina</dc:creator>
      <dc:date>2025-06-04T07:43:43Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard Access Policies/Permissions</title>
      <link>https://community.dynatrace.com/t5/Dashboarding/Dashboard-Access-Policies-Permissions/m-p/295586#M5702</link>
      <description>&lt;P&gt;I have an issue; I am a DT admin and want to view all dashboards created in the tenant. But it looks like until the user explicitly shares it with me, I cannot view it. Is it by design?&amp;nbsp; Because it was not the case with managed.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2026 22:37:47 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dashboarding/Dashboard-Access-Policies-Permissions/m-p/295586#M5702</guid>
      <dc:creator>SSelvaraj11</dc:creator>
      <dc:date>2026-03-03T22:37:47Z</dc:date>
    </item>
    <item>
      <title>Re: Dashboard Access Policies/Permissions</title>
      <link>https://community.dynatrace.com/t5/Dashboarding/Dashboard-Access-Policies-Permissions/m-p/295587#M5703</link>
      <description>&lt;P&gt;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/34063"&gt;@SSelvaraj11&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Since 1.328, administrator can manage dashboards, notebooks and other documents:&lt;BR /&gt;&lt;A href="https://docs.dynatrace.com/docs/shortlink/release-notes-saas-sprint-328#management-of-dashboards-notebooks-and-other-documents-for-administrators" target="_blank"&gt;https://docs.dynatrace.com/docs/shortlink/release-notes-saas-sprint-328#management-of-dashboards-notebooks-and-other-documents-for-administrators&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2026 00:13:05 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dashboarding/Dashboard-Access-Policies-Permissions/m-p/295587#M5703</guid>
      <dc:creator>AntonioSousa</dc:creator>
      <dc:date>2026-03-04T00:13:05Z</dc:date>
    </item>
  </channel>
</rss>

