Skip to content
Notifications
Clear all

How do I delegate dashboard view-only access to our management team?

5 Posts
5 Users
0 Reactions
21 Views
(@ethans)
Reputable Member
Joined: 2 months ago
Posts: 241
Topic starter   [#27485]

We're rolling out LogRhythm for security monitoring and our management team wants to see the high-level dashboards, but they definitely don't need edit rights. I can't seem to find a simple "view-only" role or permission setting for dashboards specifically.

Has anyone set this up? I need our execs to see the main threat and compliance dashboards without them accidentally changing filters or layouts. Is it a matter of creating a custom user role, or is there a built-in way I'm missing? Our SIEM admin time is limited, so hoping for a straightforward path.



   
Quote
 amyt
(@amyt)
Reputable Member
Joined: 3 months ago
Posts: 221
 

You're right, there isn't a simple one-click "view-only" toggle for dashboards. The most straightforward path we used is creating a custom user role with just the Dashboard Viewer permission.

When you create the role, uncheck everything else, especially "Dashboard Editor" and "Manage Dashboards." Then assign your execs to that role. It's a few more steps initially, but it saves you from a "help, I deleted a widget" call later.

Also, double-check the data source permissions for the reports feeding those dashboards - sometimes that's the hidden culprit for access issues.



   
ReplyQuote
(@hannahc)
Reputable Member
Joined: 2 months ago
Posts: 282
 

Totally feel your pain - that initial search for a view-only button is so real. I've set this up in LogRhythm a few times, and user728 is spot on about the custom role being the most reliable route. The "Dashboard Viewer" permission is exactly what you need for those threat and compliance dashboards.

One extra step I'd add: after you create the role, make a test user and actually log in as them. It's a bit of a pain, but you catch those weird edge cases where a report they can't see underlies a dashboard widget, or they might still have an "export" button you didn't anticipate. I spent an hour once figuring out why a CEO couldn't see a graph, and it was a single hidden data table permission.

Oh, and if your management team is large, see if you can assign the role to an AD group instead of individuals. It'll save you a ton of time down the road when someone new joins the leadership circle.


hannah


   
ReplyQuote
(@aurorab)
Reputable Member
Joined: 3 months ago
Posts: 340
 

Yeah, that first search for a view-only button can be a bit disappointing, can't it? The custom role route is definitely the way. I'd echo what others said about the "Dashboard Viewer" permission.

One thing I'd stress from the marketing automation side is to think of this like a customer journey. Map out exactly what they need to see from login to dashboard and nothing more. That mindset helps you catch permissions you might otherwise miss.

Also, if your SIEM admin time is tight, batch the work. Create the role, then make a quick checklist of the specific dashboards and reports they need. Assigning it to an AD group later is a lifesaver when someone new joins the management team. Saved me so many one-off requests.


don't spam bro


   
ReplyQuote
(@hiroyuki)
Estimable Member
Joined: 2 months ago
Posts: 156
 

That "customer journey" way of thinking is a great idea, thanks. It makes the permission check more logical. Do you find it helps to literally write down each click from login to final view? I might try that.

Also, what's the rule of thumb for batching? Like, set a timer for 30 minutes and just get through as many roles/dashboards as possible?


Still learning.


   
ReplyQuote