EnableYourData.nl

Platform · Module · Access and security

Everyone sees what they're meant to see. No more, no less.

In ENABLE you use access profiles to decide which dashboards and apps someone can open, and Power BI row-level security (RLS) to decide which rows of data they see within them. Around that sit two-factor authentication by email, automatic sign-out, encrypted secrets and an activity log. So you can share dashboards widely without keeping track of separate permissions for each report.

Power BI row-level security means two people can open the same dashboard and each still see only their own figures: their region, their branch, their customers. In ENABLE you link those Power BI roles to access profiles or to a tag per user. When a dashboard opens, ENABLE passes the right role to Power BI, so the filtering happens in the model itself.

Row filtering is the second layer. The first layer is dashboard access: which dashboards and apps someone can open at all. You manage that with access profiles, in one matrix for the whole organisation. Anyone without a profile sees no dashboards.

Features

What Access and security does

Access profiles

An access profile bundles the dashboards and apps a group of users can open, for example Sales team or Management. Someone can have multiple profiles; their access is then combined.

Dashboard access matrix

The "Dashboard access" page shows all profiles against all dashboards. One tick changes access for everyone with that profile, and you see in advance how many users it affects.

Invite and import

Client admins invite users by email; the invitation is valid for seven days. For large groups, platform admins import users in one go, with role and profiles.

Preview as user

See the portal the way a specific user sees it, with exactly their dashboards and apps. That way you test a change to profiles before anyone has to call about it.

Row-level security

Link Power BI roles to access profiles per dashboard, or give a user their own tag with a role and optionally CUSTOMDATA(). RLS is off by default and is switched on per dashboard.

Two-factor authentication by email

After the password comes a 6-digit code by email, valid for 5 minutes and with a maximum of 5 attempts. Can be made mandatory per organisation.

Sessions and automatic sign-out

Users see their active sessions and can sign out all other sessions. After 30 minutes without activity they are signed out automatically; the client admin chooses a value between 5 and 480 minutes.

Activity log

Client admins see recent actions in their portal, such as invitations, access changes, executed queries and published endpoints. Platform admins have an event log that includes embed sessions.

Manage dashboard access with access profiles

ENABLE works with three roles: platform admin (Data Analytics), client admin and user. Client admins always see all of their organisation's dashboards for management purposes. For regular users, access profiles determine what they see. One account can belong to multiple organisations, with a separate role in each.

That is role-based access to data in practice: you assign permissions to a role or team, not to individuals. A new colleague in sales gets the Sales team profile and immediately has the right dashboards.

Who can do whatPlatform adminClient adminUser
View dashboardsAll organisationsAll in own organisationVia access profile
Invite usersYesYesNo
Manage profiles and matrixYesYesNo
Set up RLS roles and tagsYesAssign existing tagsNo
Configure automatic sign-outYesYesNo
Make two-factor authentication mandatoryYesNoNo
View logEvent logActivity logNo

Power BI row-level security in the portal

Row-level security is off by default in ENABLE and is switched on per dashboard. There are two ways to determine which Power BI role someone gets. Via profiles, you link each access profile to a role in the Power BI model. Via a user tag, you give an individual user their own tag, which points to a role and optionally passes a value for CUSTOMDATA().

Platform admins define the tags and roles; client admins assign existing tags to users. A setting only becomes active once Power BI has validated the configuration. When a dashboard opens, ENABLE then requests an embed token with the right role, so Power BI filters the rows.

An important design principle: if a user in tag mode has no tag, they get no access. There is no fallback to a shared account with unfiltered data. Better a message than figures someone should never have seen.

Sign-in and sessions

Users sign in with their email address and their own password. Fixed rules apply:

  • Passwords have at least 12 characters, with an uppercase letter, a lowercase letter and a digit, and are stored as a scrypt hash.
  • Two-factor authentication by email: a 6-digit code, valid for 5 minutes, maximum 5 attempts.
  • A session lasts at most 8 hours; after inactivity, automatic sign-out happens sooner (30 minutes by default).
  • Changing your password automatically signs you out on other devices.
  • A password reset link is valid for one hour.
  • Sign-in attempts, codes and password resets are rate-limited to prevent guessing and abuse.

The technology behind the scenes

Secrets, such as the database connection password and the Microsoft Entra service principal secret for Power BI, are stored encrypted with AES-256-GCM. Each organisation can have its own Power BI connection. An embed token only grants read permissions on the one report being opened, and is renewed automatically for as long as someone is viewing.

The portal sends strict security headers, including a Content Security Policy, HSTS and a ban on embedding in other sites. ENABLE runs on Vercel in the Frankfurt region (fra1). Every embed session is logged, including when access is denied, along with the reason.

In ENABLE

How to set up access with ENABLE

  1. 01

    Set up profiles

    Create access profiles per team or role and choose in the matrix which dashboards and apps belong to each profile.

  2. 02

    Decide on row filtering

    Decide per dashboard whether RLS is needed. Platform admins link the profiles or tags to the roles in your Power BI model and validate the setting.

  3. 03

    Invite users

    Invite users by email and give them one or more profiles. Choose the sign-out time and, if you wish, have two-factor authentication made mandatory.

  4. 04

    Check

    Use "Preview as user" to see what someone really sees, and keep an eye on the activity log.

FAQ

Frequently asked questions

How does Power BI row-level security work in ENABLE?

ENABLE links access profiles or a tag per user to a role in your Power BI model, optionally with a CUSTOMDATA() value. When a dashboard opens, ENABLE requests an embed token with that role, so Power BI filters the rows itself.

What happens if a user has no RLS tag?

Then they get no access to that dashboard. ENABLE never falls back to a shared account with unfiltered data; a missing tag results in a message, not the wrong figures.

How do I manage dashboard access for many users?

With access profiles. You link dashboards and apps to a profile, such as Sales team, and give users one or more profiles. In the dashboard access matrix you change access for everyone with that profile at once.

Does ENABLE support two-factor authentication?

Yes, by email. After entering their password, the user receives a 6-digit code that is valid for 5 minutes, with a maximum of 5 attempts. Two-factor authentication can be made mandatory per organisation.

Can I sign in with Microsoft Entra ID?

Not yet for end users. Users sign in with email and their own password, optionally with two-factor authentication. Sign-in with Microsoft Entra ID is on the roadmap. The connection to Power BI itself does run through a Microsoft Entra service principal.

Where is ENABLE data hosted?

The portal runs on Vercel in the Frankfurt region (fra1). Your organisation's data warehouse is hosted wherever you or your data provider host it; ENABLE connects to it securely and runs only read-only queries.

Share securely, live fast, no headache

In an online demo we show you the portal: dashboards per role, row-level security, plain-language questions and how we set it up and manage it for you.