Ravindra BagaleCourses & study guides Track your progress

Guides

Workspaces and Roles in the Power BI Service

A workspace is the folder in the Power BI Service for related items: semantic models, reports, dashboards, and apps. Roles decide who can build and who can only view. My workspace is your private drawer. A team workspace is the shared cupboard.

Friends! Publishing into My workspace feels fast until you are on leave and nobody can update the FreshBasket report. Why roles? Because a viewer should see Mumbai 150, not delete the model. How? We put the report in a team workspace, give builders Member or Contributor, and give managers Viewer. Viewer is also the role where row-level security can do its job.

Quick answer

Vertical path:

  1. Create a team workspace for FreshBasket. Leave My workspace for practice.
  2. Admin manages access and can delete the workspace.
  3. Member can publish, edit, share, and update an app.
  4. Contributor can build content, and by default cannot share or manage access.
  5. Viewer can use the report. This is the role for consumers.
  6. Do not give every manager Member “to make life easy”. They would see all rows even when a security role exists.
Builders: Admin / Member / Contributor
Consumers: Viewer (or an app)

What each person should see

Person Role Mumbai card Can delete the model?
You, the author Member or Admin 150 Yes, if Admin or with rights
A colleague who edits pages Contributor 150 They can edit content, not manage access
The city manager Viewer 150, or only their city if security is on No
  1. The three sales rows still total 190 for someone who is allowed to see every city.
  2. A Viewer is not a weaker copy of the file. It is a permission.
  3. If two people must edit, they need a build role. If twenty people must read, they need Viewer or an app, not twenty Members.

What do I need before this guide?

Before and after (look at the tables first)

Before team workspace Report stuck in My workspace.

Before - My workspace. Managers are locked out

After workspace roles Viewer and member roles in a team workspace.

After - Roles. Consumers are Viewers

How to set the workspace

Workspace roles Workspace roles. Admin — manage access Member — publish, share, update app Contributor — edit content Viewer — read only Workspace roles Admin — manage access Member — publish, share, update app Contributor — edit content Viewer — read only

Admin, Member and Contributor build. Viewer only reads.

  1. In the Service, Workspaces → New workspace. Name it FreshBasket. Skip My workspace.
  2. Open access. Add yourself as Admin or Member.
  3. Add editors as Contributor unless they must also share and update the app. Then they need Member.
  4. Add readers as Viewer. Prefer a security group over typing twenty names.
  5. Confirm the report and the semantic model both live in this workspace.
  6. Ask a Viewer to open the report. They should see the pages, not the workspace settings.
  7. Write the role list down. Future you will forget who was “just added for a day”.
Consumers are Viewers Consumers are Viewers. Viewer opens the report. Viewer does not delete the model. Row-level security applies to Viewers. Builders still see every city. Consumers are Viewers Viewer opens the report. Viewer does not delete the model. Row-level security applies to Viewers. Builders still see every city.

Give consumers the Viewer role so row-level security can limit their rows. Builders see every city.

Separate development and production workspaces if your team is ready. A manager should open production. You can break things in development. Deployment pipelines are a later, capacity-based tool. You do not need them to understand roles.

Why Viewer is the consumer role

  1. Row-level security restricts viewers. It does not restrict Admins, Members, or Contributors. They can see all rows.
  2. That is not a trick. It is why builders must not be the audience.
  3. If the Pune manager is a Member, a Pune role will look “broken” because they still see Mumbai’s 150.
  4. Fix the role. Do not weaken the security filter to match the mistake.
  5. Apps, in the next guide, are the usual front door for those Viewers.

Mistakes and calm fixes

Symptom Likely cause Fix
Nobody else sees the report It sits in My workspace Publish to the team workspace
A reader deleted a report They were Member or Admin Drop them to Viewer
Security role seems ignored The person is a builder role Give them Viewer or app access
Too many owners Everyone is Admin One or two Admins, then Members

Ravindra Bagale's Tip

Interview line: “I publish to a team workspace. Builders get Member or Contributor. Consumers get Viewer, because row-level security applies to viewers.” Got it?

Practice task

  1. Create a practice workspace with a clear name.
  2. List four roles and one job each.
  3. Put a classmate or a test account as Viewer.
  4. Confirm they can open the report and cannot manage access.
  5. Write why My workspace is the wrong home for FreshBasket.

Learn it properly

Course lesson:

Related: Publish · Row-level security

Got it? A workspace holds the items. The role decides build versus view. Consumers are Viewers. Next: an app, so they do not wander around the workspace at all. Let us go ahead.

Frequently asked questions

What is a workspace?

A container in the Service for semantic models, reports, dashboards, and apps.

What is My workspace?

Your personal area. Fine for practice. Wrong home for a team report.

Who should be Viewer?

Anyone who should read the report and not change it.

Why does security fail for a Member?

Row-level security applies to viewers, not to Admin, Member, or Contributor.

How many Admins?

Few. Too many Admins means too many people can delete the workspace.

Course lesson?

Workspaces and roles, in the Power BI Service chapter.