Understanding permissions in reports

Language: English

In ActivityInfo, reports are a powerful way to analyze and present data stored in your database. Permissions play an important role in determining who can view, create, and manage these reports, as well as what data is visible within them.

There are a few key concepts to understand regarding this:

1. Viewing and creating reports

In ActivityInfo, any user has the ability to create their own reports on data that they have access to, regardless of their specific permissions. However, the ability to save the report as a resource within the database is strictly determined by the permissions assigned to their roles.
If a user does not have the "Add forms, folders, and reports" permission, they can still create a report; but it will be saved as a personal report under "My reports" rather than as a resource in the database.

  • Users can open and interact with reports they have permission to access.
  • Users can add reports to a database only if their role has the "Add forms, folders, and reports" permission.
  • Users can edit reports and customize them to their liking and save them under "My reports".

2. Report types and locations

Depending on its status, reports can be:

  • Personal: These reports are saved under "My reports" and can be viewed only by the designer, unless the designer shares the report with specific roles in a database using the "Share reports" permission.
  • Published: These reports can be viewed by anyone with the link, including individuals who are not ActivityInfo users.
  • Part of a database: These reports can be viewed by users who are added to the database and have access to a folder containing the report.

3. Editing reports

Editing a report in a database is not available to all users; specific permissions and form access levels determine who can make changes.

  • To edit a report, users must have the "Edit forms, folders, and reports" permission, along with view access to all underlying forms in the report that belong to the same database as the report.
  • Forms included in the report that belong to a different database must have public visibility, or the user must have the "Publish reports" permission for those forms.

4. Moving reports

Reports can be moved as needed, provided the user has the appropriate permissions.

  • You can move a report to another database, folder, or to "My reports".
  • Moving a report requires the "Delete forms, folders and reports" permission from the original location and "Add forms, folders, and reports" for the destination.

5. The “Publish reports” permission

This permission refers specifically to making a report accessible to anyone with the link, without requiring an ActivityInfo account.

  • The publish reports permission is sensitive and should only be granted to users trusted to exercise good judgment over who can access the data.
  • Personal reports and reports saved in a database can both be published.
  • If a user role is granted the "Publish reports" permission and uses it to publish a report, revoking that permission later does not unpublish the report; it remains accessible via its link.
  • Users can edit a published report if they have the "Edit forms, folders, and reports" permission, or if they are the designer of a personal report.

6. Data visibility within reports

The data visible in a report depends on where the report is located and how it was shared.

  • For reports saved in a database, and for published reports, users see the data the creator included, regardless of their own record-level conditions or role parameters.
  • If the report creator has record-level conditions applied to their own role, they will only be able to include the records they are permitted to see in the reports they create.
  • For personal reports shared with specific roles using the "Share reports" permission, each viewer sees the report's data filtered according to their own record-level conditions.
  • Users with the "View all records" permission can view a report, provided it is located within a resource to which they have access.

7. Cross-database reports

ActivityInfo allows forms from different databases to be combined in a single report.

  • To view or copy a report that combines forms from different databases, you need at least permission to view those forms.
  • To save or share the report, you need the "Publish reports" permission for the forms that belong to the other databases, or those forms must have public visibility.

Best Practice: Partner-Specific Reporting

When working in multi-partner environments, it is important to ensure that each partner only has access to the data relevant to them. When a report is included in a database, users added to that database can view, edit, and interact with it based on their respective permissions, making it essential to structure reports thoughtfully when data confidentiality is a concern.
To securely share data with partners in a multi-partner environment, the recommended approach is:

  • Create separate reports for each partner.
  • Apply specific filters (such as partner ID or geographic location) to each individual report.
  • Grant access only to the specific reports relevant to that partner to maintain data confidentiality.
Next item
Explanation