AddThisFeature

Report Sharing Permissions

Share a report with specific people without opening the data behind it.

moderate Analytics

What it adds

Per-report access control inside the app, distinguishing what each recipient may do with the report.

What your agent is told to do

5
  1. 1

    Give each saved report its own access list, separate from the workspace-wide role. Reports combine data that not everyone should see together.

  2. 2

    Model four distinct grants: view, edit, duplicate, and reshare. Being able to read a report is not permission to hand it to someone else.

  3. 3

    Enforce the underlying data permissions on every render. A share grants access to the report definition, never a bypass of row-level security on the source.

  4. 4

    Show the current access list on the report, so an owner can see who can open it without digging through settings.

  5. 5

    Do NOT build account-less public links here — tokenized external sharing is owned by Signed Share Links. Role definitions are owned by User Roles; read from them rather than defining new roles.

Edge cases it handles

6
  • A recipient without access to a source must see that widget explained, not a blank panel or a raw permission error.
  • Removing someone from the workspace must revoke their report shares immediately, not leave an orphaned grant.
  • A duplicated report must not inherit the original's access list by default — the copy starts with the duplicator.
  • Downgrading a user's workspace role must narrow their report access too; the more restrictive of the two wins.
  • An owner leaving must not strand a report with no one able to manage it. Reassign ownership or block the departure.
  • Aggregate figures can leak restricted rows. If a recipient cannot see the underlying rows, do not show them the total derived from those rows.

Definition of done

8
  • Each saved report has its own access list independent of workspace roles.
  • View, edit, duplicate, and reshare are separately grantable.
  • Row-level security on source data is enforced for every viewer, sharer or not.
  • Losing workspace membership revokes report access with no delay.
  • Widgets a recipient cannot see are explained rather than silently blank or broken.
  • A duplicated report does not carry the original's shares.
  • The feature matches the existing design system.
  • No existing functionality is broken.

Related features

How it works

  1. 1

    Copy the link

    Grab the Markdown instruction URL for this feature.

  2. 2

    Give it to your AI

    Paste it into Claude Code, Cursor, v0, Lovable — whatever you build with.

  3. 3

    It inspects, then implements

    Your agent reads your existing app first, then adds the feature to fit it.

Works with your stack

These instructions are written to adapt. They tell the agent to detect your framework, match your existing design system, and reuse what you already have — rather than assuming a particular stack.

Need it tighter than that? Customize the feature and tell it exactly what you're running.