<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DQL available for viewing and modifying in Dashboards Tiles with viewer role in Dashboarding</title>
    <link>https://community.dynatrace.com/t5/Dashboarding/DQL-available-for-viewing-and-modifying-in-Dashboards-Tiles-with/m-p/300790#M5820</link>
    <description>&lt;P&gt;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/94111"&gt;@luisbsantos&lt;/a&gt;&amp;nbsp;If you are giving access to a dashboard for a user , you may not be able to block that user from running queries based on the way permissions work in Dynatrace at this point of time.&amp;nbsp; When a user tries to access a dashboard the system would need to execute a DQL query in the backend to fetch the data based on the user permissions. So, we may not be able to allow dashboard access while explicitly preventing DQL execution.&lt;/P&gt;&lt;P&gt;If the concern is about unauthorized data access you can try limiting the access to data with policies instead&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 16 Jun 2026 01:11:32 GMT</pubDate>
    <dc:creator>p_devulapalli</dc:creator>
    <dc:date>2026-06-16T01:11:32Z</dc:date>
    <item>
      <title>DQL available for viewing and modifying in Dashboards Tiles with viewer role</title>
      <link>https://community.dynatrace.com/t5/Dashboarding/DQL-available-for-viewing-and-modifying-in-Dashboards-Tiles-with/m-p/300783#M5818</link>
      <description>&lt;P&gt;I am working on some Dashboards that will be shared with other teams. My current solution, after trying to give the least possible available permissions, still lets anyone not only see but also modify and run DQL queries however they want - they just can't save the dashboard afterwards.&lt;/P&gt;&lt;P&gt;So a user with the least possible permissions (viewer only) can go to a simple dashboard, modify the DQL to something as simple as "fetch events" and have access to all the events within the timeframe. Or any other DQL query.&lt;/P&gt;&lt;P&gt;I tried restricting the accessm through exploring the Users/Groups Policies and also the Boundaries, but the only working solutions I got still let me run DQL queries with my test user.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know how can I disable/block this behaviour?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2026 18:19:30 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dashboarding/DQL-available-for-viewing-and-modifying-in-Dashboards-Tiles-with/m-p/300783#M5818</guid>
      <dc:creator>luisbsantos</dc:creator>
      <dc:date>2026-06-15T18:19:30Z</dc:date>
    </item>
    <item>
      <title>Re: DQL available for viewing and modifying in Dashboards Tiles with viewer role</title>
      <link>https://community.dynatrace.com/t5/Dashboarding/DQL-available-for-viewing-and-modifying-in-Dashboards-Tiles-with/m-p/300790#M5820</link>
      <description>&lt;P&gt;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/94111"&gt;@luisbsantos&lt;/a&gt;&amp;nbsp;If you are giving access to a dashboard for a user , you may not be able to block that user from running queries based on the way permissions work in Dynatrace at this point of time.&amp;nbsp; When a user tries to access a dashboard the system would need to execute a DQL query in the backend to fetch the data based on the user permissions. So, we may not be able to allow dashboard access while explicitly preventing DQL execution.&lt;/P&gt;&lt;P&gt;If the concern is about unauthorized data access you can try limiting the access to data with policies instead&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jun 2026 01:11:32 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dashboarding/DQL-available-for-viewing-and-modifying-in-Dashboards-Tiles-with/m-p/300790#M5820</guid>
      <dc:creator>p_devulapalli</dc:creator>
      <dc:date>2026-06-16T01:11:32Z</dc:date>
    </item>
    <item>
      <title>Re: DQL available for viewing and modifying in Dashboards Tiles with viewer role</title>
      <link>https://community.dynatrace.com/t5/Dashboarding/DQL-available-for-viewing-and-modifying-in-Dashboards-Tiles-with/m-p/300819#M5822</link>
      <description>&lt;P&gt;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/21657"&gt;@p_devulapalli&lt;/a&gt;&amp;nbsp;thank you for your response!&lt;/P&gt;&lt;P&gt;I obviously want the Dashboard to execute DQL - I need to display data with it so the clients can actually observe their systems. What I am very uncomfortable allowing is in any user being able to see and execute DQL queries after the initial DQL queries are displayed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've been reading the Dynatrace documentation but couldn't solve the &lt;EM&gt;unauthorized data access&lt;/EM&gt; problem with policies, but I'm still on this (specially around the IAM policy reference - link&amp;nbsp;&lt;A href="https://docs.dynatrace.com/docs/manage/identity-access-management/permission-management/manage-user-permissions-policies/advanced/iam-policystatements" target="_self"&gt;here&lt;/A&gt;) Do you have any suggestion that might be useful?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jun 2026 11:08:59 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dashboarding/DQL-available-for-viewing-and-modifying-in-Dashboards-Tiles-with/m-p/300819#M5822</guid>
      <dc:creator>luisbsantos</dc:creator>
      <dc:date>2026-06-16T11:08:59Z</dc:date>
    </item>
  </channel>
</rss>

