Illustrative example · Sample data

Sharing & access

How to Share Business Dashboards Securely with Your Team

Use a report catalog, explicit permissions and a small access test to make sharing more useful without treating every link as authorization.

Illustrative report catalog connected to three authorized-user symbols.

Sharing a dashboard securely means deciding who should see which information, enforcing that decision and checking that the result matches it. A portal can make the experience easier, but a polished report catalog is not evidence that access has been configured correctly.

Start with the audience and the data. Then test the same experience that a normal recipient will use—not just the administrator’s view.

Define what each audience needs

Write a short access map before inviting people. For a sales report, an owner might need all regions, a manager might need one region, and an external adviser might need only an aggregated summary. Those are different requirements.

If a tool cannot enforce a necessary restriction, change the report or do not share it with that audience. A page filter that viewers can clear is not a substitute for an enforced data-access restriction.

Also distinguish access to a whole report from access to particular records inside it. You may need one, the other or both. Do not assume that inviting someone to a workspace automatically implements your intended row-level rules.

Treat sign-in and permission as separate checks

Sign-in answers “Who is this user?” Authorization answers “What may this user access?” Both matter. A work-account login can identify a person without granting the right to see every client report.

For the distinction between identity verification and permission to act, see the OWASP authorization guidance.

For each role, decide whether users can administer the workspace, create or edit reports, or only view approved content. Give people the level of access required for the task rather than broad access for convenience.

Timeliq’s product scope combines Microsoft 365 sign-in with invitations, roles and report permissions. Those controls still need to be configured and tested for the actual workspace and connected sources.

Give the current report a clear home

A report catalog helps people find the right version without searching through old messages. Use meaningful names and descriptions: “Monthly sales — approved management view” communicates more than “Final dashboard v7.”

Add enough context for a person to understand the report’s purpose, data period and owner. Only show a refresh timestamp when it comes from the actual refresh process; a manually changed “updated” label can create false confidence.

A secure link can take a recipient to the report, but the access decision belongs behind that link. Forwarding the address should not expand someone else’s permissions.

Run an access test with contrasting users

Use non-sensitive sample data and at least two test identities. A simple test matrix is often more useful than checking only that the owner can open the page.

Test

Expected result

Authorized viewer opens an assigned report

Only the permitted report and data are available

Viewer opens an unassigned report URL

Access is denied without revealing the report’s data

Client A tries to open Client B’s report

Access is denied

Removed member returns through a saved link

The revoked access is not restored by the link

Viewer tries an editing action

It is unavailable unless the role permits editing

Record the behavior you actually observe. The table is a proposed test, not a statement that a particular deployment has passed it.

Check chat destinations as well as portal access

When data questions are available through messaging, ask where the answer will appear. A shared channel or group can have a different audience from the person who asked the question. Notifications, forwarded messages and personal devices may also expose a response beyond the original screen.

Authorize the identity and destination, limit the detail to what that audience needs, and avoid using a broad group for sensitive answers. Revoking portal access should lead you to review channel access too; do not assume every connected system updates automatically.

Make access review part of maintenance

Name a report owner and a person responsible for access. Review permissions when someone changes roles, a client engagement ends or the data becomes more sensitive. This is an operational practice, not a one-time setup screen.

Explore Portal and access in Timeliq, or read how to organize separate client workspaces. The objective is a report that is easy for the right people to use—and unavailable to everyone else.

Put the idea to work with your own reporting.

Explore how Timeliq brings editable dashboards, sharing and data questions together.