Workspaces and Roles in the Power BI Service
A workspace is the folder in the Power BI Service for related items: semantic models, reports, dashboards, and apps. Roles decide who can build and who can only view. My workspace is your private drawer. A team workspace is the shared cupboard.
Friends! Publishing into My workspace feels fast until you are on leave and nobody can update the FreshBasket report. Why roles? Because a viewer should see Mumbai 150, not delete the model. How? We put the report in a team workspace, give builders Member or Contributor, and give managers Viewer. Viewer is also the role where row-level security can do its job.
मित्रांनो! My workspace मध्ये publish करणे जलद वाटते, जोपर्यंत तुम्ही रजेवर नसाल आणि FreshBasket report कोणी अपडेट करू शकत नाही. Roles का? कारण viewer ने Mumbai 150 बघायला हवे, model डिलीट करायला नको. कसे? Report team workspace मध्ये, builders ला Member किंवा Contributor, managers ला Viewer. Viewer हीच role आहे जिथे row-level security काम करते.
मित्रों! My workspace में publish करना तेज़ लगता है, जब तक आप छुट्टी पर न हों और FreshBasket report कोई अपडेट न कर सके. Roles क्यों? क्योंकि viewer को Mumbai 150 देखना है, model डिलीट नहीं करना. कैसे? Report team workspace में, builders को Member या Contributor, managers को Viewer. Viewer वही role है जहाँ row-level security काम करती है.
Quick answer
Vertical path:
- Create a team workspace for FreshBasket. Leave My workspace for practice.
- Admin manages access and can delete the workspace.
- Member can publish, edit, share, and update an app.
- Contributor can build content, and by default cannot share or manage access.
- Viewer can use the report. This is the role for consumers.
- Do not give every manager Member “to make life easy”. They would see all rows even when a security role exists.
Builders: Admin / Member / Contributor
Consumers: Viewer (or an app)
What each person should see
| Person | Role | Mumbai card | Can delete the model? |
|---|---|---|---|
| You, the author | Member or Admin | 150 | Yes, if Admin or with rights |
| A colleague who edits pages | Contributor | 150 | They can edit content, not manage access |
| The city manager | Viewer | 150, or only their city if security is on | No |
- The three sales rows still total 190 for someone who is allowed to see every city.
- A Viewer is not a weaker copy of the file. It is a permission.
- If two people must edit, they need a build role. If twenty people must read, they need Viewer or an app, not twenty Members.
What do I need before this guide?
- A report already published (publish).
- Course: Workspaces and roles.
Before and after (look at the tables first)
Before - My workspace. Managers are locked out
आधी (Before) — My workspace. Managers बाहेर.
पहले (Before) — My workspace. Managers बाहर.
After - Roles. Consumers are Viewers
नंतर (After) — Roles. Consumers हे Viewers.
बाद में (After) — Roles. Consumers Viewer हैं.
How to set the workspace
Admin, Member and Contributor build. Viewer only reads.
Admin, Member आणि Contributor बनवतात. Viewer फक्त वाचतो.
Admin, Member और Contributor बनाते हैं. Viewer सिर्फ पढ़ता है.
- In the Service, Workspaces → New workspace. Name it FreshBasket. Skip My workspace.
- Open access. Add yourself as Admin or Member.
- Add editors as Contributor unless they must also share and update the app. Then they need Member.
- Add readers as Viewer. Prefer a security group over typing twenty names.
- Confirm the report and the semantic model both live in this workspace.
- Ask a Viewer to open the report. They should see the pages, not the workspace settings.
- Write the role list down. Future you will forget who was “just added for a day”.
Give consumers the Viewer role so row-level security can limit their rows. Builders see every city.
Consumers ला Viewer role द्या म्हणजे row-level security त्यांच्या rows मर्यादित करू शकेल. Builders प्रत्येक city बघतात.
Consumers को Viewer role दें ताकि row-level security उनकी rows सीमित कर सके. Builders हर city देखते हैं.
Separate development and production workspaces if your team is ready. A manager should open production. You can break things in development. Deployment pipelines are a later, capacity-based tool. You do not need them to understand roles.
Why Viewer is the consumer role
- Row-level security restricts viewers. It does not restrict Admins, Members, or Contributors. They can see all rows.
- That is not a trick. It is why builders must not be the audience.
- If the Pune manager is a Member, a Pune role will look “broken” because they still see Mumbai’s 150.
- Fix the role. Do not weaken the security filter to match the mistake.
- Apps, in the next guide, are the usual front door for those Viewers.
Mistakes and calm fixes
| Symptom | Likely cause | Fix |
|---|---|---|
| Nobody else sees the report | It sits in My workspace | Publish to the team workspace |
| A reader deleted a report | They were Member or Admin | Drop them to Viewer |
| Security role seems ignored | The person is a builder role | Give them Viewer or app access |
| Too many owners | Everyone is Admin | One or two Admins, then Members |
Ravindra Bagale's Tip
Interview line: “I publish to a team workspace. Builders get Member or Contributor. Consumers get Viewer, because row-level security applies to viewers.” Got it?
Ravindra Bagale's Tip – मराठी
Interview line: “मी team workspace मध्ये publish करतो. Builders ला Member किंवा Contributor. Consumers ला Viewer, कारण row-level security viewers ला लागू होते.” समजलं का?
Ravindra Bagale's Tip – हिंदी
Interview line: “मैं team workspace में publish करता हूँ. Builders को Member या Contributor. Consumers को Viewer, क्योंकि row-level security viewers पर लागू होती है.” समझ में आया?
Practice task
- Create a practice workspace with a clear name.
- List four roles and one job each.
- Put a classmate or a test account as Viewer.
- Confirm they can open the report and cannot manage access.
- Write why My workspace is the wrong home for FreshBasket.
Got it? A workspace holds the items. The role decides build versus view. Consumers are Viewers. Next: an app, so they do not wander around the workspace at all. Let us go ahead.
समजलं का? Workspace items ठेवतो. Role ठरवते build की view. Consumers हे Viewers. पुढे: app, म्हणजे ते workspace मध्ये भटकणार नाहीत. आता पुढे जाऊया.
समझ में आया? Workspace items रखता है. Role तय करती है build या view. Consumers Viewer होते हैं. आगे: app, ताकि वे workspace में भटकें नहीं. अब आगे बढ़ते हैं.
Frequently asked questions
What is a workspace?
A container in the Service for semantic models, reports, dashboards, and apps.
What is My workspace?
Your personal area. Fine for practice. Wrong home for a team report.
Who should be Viewer?
Anyone who should read the report and not change it.
Why does security fail for a Member?
Row-level security applies to viewers, not to Admin, Member, or Contributor.
How many Admins?
Few. Too many Admins means too many people can delete the workspace.
Course lesson?
Workspaces and roles, in the Power BI Service chapter.