What you will be able to do
- Publish a dashboard and choose between shared data permissions and individual data permissions
- Share a published dashboard with workspace users and groups at the right permission level
- Share with account users who have no workspace access, and explain who a copied dashboard link actually works for
Key concept
Who runs the queries (shared vs individual data permissions) — When you publish a dashboard you choose whose credentials run its queries. With shared data permissions, viewers see data through the publisher's access. With individual data permissions, each viewer sees only what their own access allows.
1.Publish before you share, and choose whose data access viewers get
An AI/BI dashboard exists in two forms: the draft you edit and the published version that viewers open. You have to publish before you can share. Publishing takes a snapshot. That snapshot stays the same until you publish again, so you can keep editing the draft without anything changing for your viewers.
To publish, open the draft and click Publish in the upper-right corner. You then choose one of two data permission options. Share data permissions is the default. Viewers' queries run with the publisher's permissions, so people without direct access to the tables can still see results. The documentation warns that this might expose data to users who have not been granted direct access to it. The Publisher Credential field defaults to your own user account. To publish with a service principal's credentials instead, use the kebab menu next to the option. Individual data permissions means each viewer's queries run with their own credentials, so they need access to the underlying data. Whichever option you pick, the publisher's credentials always provide compute access.
| Publishing option | Who runs queries | Data access determined by | Best for |
|---|---|---|---|
| Share data permissions (default) | Publisher | Publisher’s permissions | Consistent experience for users without workspace access |
| Individual data permissions | Each viewer | Viewer’s own permissions | Users with direct data permissions, including account users who do not require workspace membership |
Checkpoint 1 of 6· Put it in order
Put the steps for publishing a dashboard in order
- 1.Click Publish to confirm
- 2.Click Publish in the upper-right corner
- 3.Choose Share data permissions or Individual data permissions
- 4.Open the draft dashboard
- 5.Use the Sharing dialog, which opens automatically, to share the published dashboard
You start from the draft, pick a data permission option in the Publish flow, and confirm. The Sharing dialog then opens by itself.
“After you publish, the Sharing dialog opens automatically, allowing you to immediately share the published dashboard.”Source: docs.databricks.com
Sources1
2.Share with workspace users and groups
Once the dashboard is published, open it (draft or published) and click Share. At the top of the Sharing dialog, enter the users and groups you want to share with, assign each a permission level such as CAN EDIT or CAN MANAGE, and click Add. To share with everyone in the workspace, add the system group All workspace users instead of adding people one at a time.
| Permission level | Allows |
|---|---|
| CAN_READ | Can view the Lakeview dashboard |
| CAN_RUN | Can view, attach/detach, and run the Lakeview dashboard |
| CAN_EDIT | Can view, attach/detach, run, and edit the Lakeview dashboard |
| CAN_MANAGE | Can view, attach/detach, run, edit, and change permissions of the Lakeview dashboard |
A permission grant is only half the picture. A user's workspace entitlement also limits what they can do. Users with the Databricks SQL entitlement can be granted access to both the draft and the published dashboard, but they need at least CAN EDIT to modify and republish a draft. Users with the Consumer access entitlement can run the dashboard, apply filters, interact with visualizations, and share the dashboard URL with other workspace users. They cannot create or edit dashboards or change sharing settings.
Permissions also come from the folder a dashboard is stored in. Dashboards inherit the workspace permissions of their enclosing folder, which by default is /Workspace/Users/<username>, so anyone with access to that folder can open the dashboard. Ownership gives no extra power: the owner has the same access as any user with CAN MANAGE. Only workspace admins can transfer ownership.
Checkpoint 2 of 6· Check yourself
An analyst has the Consumer access entitlement and has been granted access to a published dashboard. What can they do?
Consumer access is read-and-run only. These users can interact with the dashboard and pass its URL on, but they cannot edit it or change its sharing.
“Users with the Consumer access entitlement are restricted to read-and-run-only access.”Source: docs.databricks.com
Checkpoint 3 of 6· Exam question
An analyst publishes an AI/BI dashboard and wants a workspace group to be able to view it, apply filters, and interact with its visualizations, but never modify or republish it. Which action in the dashboard's UI achieves exactly this?
Correct answer: A — Open the Sharing dialog, add the workspace group by name, and assign it the Can Run permission level, which supports viewing and filtering without any editing rights.
- A. Assigning Can Run through the Sharing dialog is the correct mechanism: it lets the named group view, filter, and interact with the published dashboard while leaving edit and republish actions unavailable to them.
- B. Can Edit grants modification and republish rights to whoever holds it, so assigning that level does not stop the group from changing the dashboard; it directly contradicts the requirement to block editing.
- C. Groups added to a dashboard do not inherit the owner's permission level by default; leaving a group unassigned means it has no access at all rather than the intended view-and-run access.
- D. A shareable link does not bypass the permission model configured in the Sharing dialog; access for its recipients still depends on the levels and identities configured there, not on the link itself.
3.Account users without workspace access, and the shareable link
You can also share with people who are registered in your Databricks account but are not members of the workspace. In the Sharing dialog you can add specific account users and groups. You can also use the Sharing settings option at the bottom of the dialog and choose Anyone in my account can view to give view access to everyone in the account. These users see a view-only copy of the published dashboard. They cannot open the draft, and the workspace navigation is hidden from them.
The Sharing dialog shows CAN EDIT, but what the user can actually do is capped at CAN RUN. The higher level only applies if they are later added to the workspace.
To send people to the dashboard, click Copy link near the bottom of the Sharing dialog. This copies a shareable URL for the published dashboard. The link is not a public pass. Before account members can open shared dashboards, an administrator must register them with the account. Login works through email and one-time passcode authentication or through unified login with SSO. Only users who are registered and have been granted access can view the dashboard. A stranger who gets the URL cannot.
There is one more limit. Account users who are not workspace members cannot see data from workspace-bound securables, such as workspace-bound catalogs, even when they have permissions on those tables. Widgets that query those objects show no data for them. To reach people who have no Databricks account at all, you need embedding for external users, not a link.
Checkpoint 4 of 6· Check yourself
You click Copy link and email the URL to a partner who has never been registered with your Databricks account. What happens when they open it?
Registering users with the account is what keeps access limited to designated people. The link alone gives no access.
“restricts access to the shared dashboard to only designated members of the account, rather than allowing anyone with the link to view it.”Source: docs.databricks.com
Checkpoint 5 of 6· Match them up
Match each sharing target to the way you grant it access
Tap a term, then the definition that fits it.
Workspace-wide and account-wide sharing use different mechanisms. Users outside the workspace can never go beyond CAN RUN.
“If you want to share with everyone in your Databricks account, use the sharing setting: Anyone in my account can view.”Source: docs.databricks.com
Checkpoint 6 of 6· Exam question
A dashboard owner wants to give a client, who has a registered account in the same Databricks account console but no access to the workspace, editing rights over a published dashboard, and assigns them Can Edit through the Sharing dialog. What actually happens?
Correct answer: A — Because the client lacks workspace access, Databricks caps their effective permission at Can Run, so they can view the dashboard but cannot edit or republish it.
- A. Databricks caps a non-workspace account member's effective permission at Can Run regardless of what level is assigned in the Sharing dialog, so the client ends up with view-and-run access only.
- B. The sharing action is not rejected; dashboards can be shared with registered account members who lack workspace access, they simply receive a view-only copy rather than an error.
- C. Registered account membership is not sufficient on its own to unlock Can Edit; the permission is silently capped down to Can Run because the client has no workspace access.
- D. Assigning Can Edit to a non-workspace account member does not trigger any access-request workflow; the permission is simply capped, and no request process is initiated for the client.
Sources1
Exam traps
Each one states something that sounds right. Open it to see what is actually true.
1.Publishing with shared data permissions means every version of the dashboard, including the draft, runs with the publisher's access.Why is that wrong?
Shared data permissions only apply to the published snapshot. Draft viewers always use their own data permissions.
Covered in Publish before you share, and choose whose data access viewers get
2.Granting CAN EDIT in the Sharing dialog lets an account user edit the dashboard even though they are not in the workspace.Why is that wrong?
The grant appears in the dialog, but users without workspace access are limited to CAN RUN until someone adds them to the workspace.
Covered in Account users without workspace access, and the shareable link
3.Copy link creates a public URL that anyone outside the organization can open.Why is that wrong?
Viewers must be registered with the Databricks account and granted access. People without accounts are reached through embedding for external users.
Covered in Account users without workspace access, and the shareable link
Sources
Every claim above is drawn from one of these pages, quoted as it was written on the date shown.
- 1.
“Publishing creates a snapshot of your dashboard that viewers can access.”
↩︎ Publish before you share, and choose whose data access viewers get“This might expose data to users who have not been granted direct access to it.”
↩︎ Publish before you share, and choose whose data access viewers get“To publish using a service principal's credentials instead, click the kebab menu next to this option and select a service principal.”
↩︎ Publish before you share, and choose whose data access viewers get“If you want to share with everyone in your workspace, use the system group: All workspace users.”
↩︎ Share with workspace users and groups“They must have at least CAN EDIT permission in order to modify and republish a draft.”
↩︎ Share with workspace users and groups“Dashboards inherit the workspace permissions set on the enclosing folder.”
↩︎ Share with workspace users and groups“Dashboard ownership does not grant special privileges.”
↩︎ Share with workspace users and groups“Click Copy link near the bottom of the Sharing dialog to copy a shareable URL for the published dashboard.”
↩︎ Account users without workspace access, and the shareable link“Dashboard account-level sharing supports email and one-time passcode authentication, and unified login with single sign-on (SSO).”
↩︎ Account users without workspace access, and the shareable link“Elevated permissions cannot be applied unless the user is added to the workspace.”
↩︎ Account users without workspace access, and the shareable link“Dashboard widgets that query workspace-bound securables do not display data for account users.”
↩︎ Account users without workspace access, and the shareable link“Share data permission (default): Viewers run queries using the publisher's data permissions.”
↩︎ Key concept“For draft dashboards, the viewer's data permissions are always applied, even if the dashboard is published with shared data permissions.”
↩︎ Exam trap 1“Users who do not have access to the workspace are limited to CAN RUN permissions.”
↩︎ Exam trap 2“rather than allowing anyone with the link to view it.”
↩︎ Exam trap 3“For draft dashboards, the viewer's data permissions are always applied, even if the dashboard is published with shared data permissions.”
↩︎ Prediction“After you publish, the Sharing dialog opens automatically, allowing you to immediately share the published dashboard.”
↩︎ Checkpoint“Users with the Consumer access entitlement are restricted to read-and-run-only access.”
↩︎ Checkpoint“restricts access to the shared dashboard to only designated members of the account, rather than allowing anyone with the link to view it.”
↩︎ Checkpoint“If you want to share with everyone in your Databricks account, use the sharing setting: Anyone in my account can view.”
↩︎ Checkpoint - 2.
“Can view, attach/detach, run, edit, and change permissions of the Lakeview dashboard”
↩︎ Share with workspace users and groups