Access profiles
An access profile bundles the dashboards and apps a group of users can open, for example Sales team or Management. Someone can have multiple profiles; their access is then combined.
Platform · Module · Access and security
In ENABLE you use access profiles to decide which dashboards and apps someone can open, and Power BI row-level security (RLS) to decide which rows of data they see within them. Around that sit two-factor authentication by email, automatic sign-out, encrypted secrets and an activity log. So you can share dashboards widely without keeping track of separate permissions for each report.
Which access profiles see which dashboards.
Power BI row-level security means two people can open the same dashboard and each still see only their own figures: their region, their branch, their customers. In ENABLE you link those Power BI roles to access profiles or to a tag per user. When a dashboard opens, ENABLE passes the right role to Power BI, so the filtering happens in the model itself.
Row filtering is the second layer. The first layer is dashboard access: which dashboards and apps someone can open at all. You manage that with access profiles, in one matrix for the whole organisation. Anyone without a profile sees no dashboards.
Features
An access profile bundles the dashboards and apps a group of users can open, for example Sales team or Management. Someone can have multiple profiles; their access is then combined.
The "Dashboard access" page shows all profiles against all dashboards. One tick changes access for everyone with that profile, and you see in advance how many users it affects.
Client admins invite users by email; the invitation is valid for seven days. For large groups, platform admins import users in one go, with role and profiles.
See the portal the way a specific user sees it, with exactly their dashboards and apps. That way you test a change to profiles before anyone has to call about it.
Link Power BI roles to access profiles per dashboard, or give a user their own tag with a role and optionally CUSTOMDATA(). RLS is off by default and is switched on per dashboard.
After the password comes a 6-digit code by email, valid for 5 minutes and with a maximum of 5 attempts. Can be made mandatory per organisation.
Users see their active sessions and can sign out all other sessions. After 30 minutes without activity they are signed out automatically; the client admin chooses a value between 5 and 480 minutes.
Client admins see recent actions in their portal, such as invitations, access changes, executed queries and published endpoints. Platform admins have an event log that includes embed sessions.
ENABLE works with three roles: platform admin (Data Analytics), client admin and user. Client admins always see all of their organisation's dashboards for management purposes. For regular users, access profiles determine what they see. One account can belong to multiple organisations, with a separate role in each.
That is role-based access to data in practice: you assign permissions to a role or team, not to individuals. A new colleague in sales gets the Sales team profile and immediately has the right dashboards.
| Who can do what | Platform admin | Client admin | User |
|---|---|---|---|
| View dashboards | All organisations | All in own organisation | Via access profile |
| Invite users | Yes | Yes | No |
| Manage profiles and matrix | Yes | Yes | No |
| Set up RLS roles and tags | Yes | Assign existing tags | No |
| Configure automatic sign-out | Yes | Yes | No |
| Make two-factor authentication mandatory | Yes | No | No |
| View log | Event log | Activity log | No |
Row-level security is off by default in ENABLE and is switched on per dashboard. There are two ways to determine which Power BI role someone gets. Via profiles, you link each access profile to a role in the Power BI model. Via a user tag, you give an individual user their own tag, which points to a role and optionally passes a value for CUSTOMDATA().
Platform admins define the tags and roles; client admins assign existing tags to users. A setting only becomes active once Power BI has validated the configuration. When a dashboard opens, ENABLE then requests an embed token with the right role, so Power BI filters the rows.
An important design principle: if a user in tag mode has no tag, they get no access. There is no fallback to a shared account with unfiltered data. Better a message than figures someone should never have seen.
Users sign in with their email address and their own password. Fixed rules apply:
Secrets, such as the database connection password and the Microsoft Entra service principal secret for Power BI, are stored encrypted with AES-256-GCM. Each organisation can have its own Power BI connection. An embed token only grants read permissions on the one report being opened, and is renewed automatically for as long as someone is viewing.
The portal sends strict security headers, including a Content Security Policy, HSTS and a ban on embedding in other sites. ENABLE runs on Vercel in the Frankfurt region (fra1). Every embed session is logged, including when access is denied, along with the reason.
In ENABLE
Create access profiles per team or role and choose in the matrix which dashboards and apps belong to each profile.
Decide per dashboard whether RLS is needed. Platform admins link the profiles or tags to the roles in your Power BI model and validate the setting.
Invite users by email and give them one or more profiles. Choose the sign-out time and, if you wish, have two-factor authentication made mandatory.
Use "Preview as user" to see what someone really sees, and keep an eye on the activity log.
FAQ
ENABLE links access profiles or a tag per user to a role in your Power BI model, optionally with a CUSTOMDATA() value. When a dashboard opens, ENABLE requests an embed token with that role, so Power BI filters the rows itself.
Then they get no access to that dashboard. ENABLE never falls back to a shared account with unfiltered data; a missing tag results in a message, not the wrong figures.
With access profiles. You link dashboards and apps to a profile, such as Sales team, and give users one or more profiles. In the dashboard access matrix you change access for everyone with that profile at once.
Yes, by email. After entering their password, the user receives a 6-digit code that is valid for 5 minutes, with a maximum of 5 attempts. Two-factor authentication can be made mandatory per organisation.
Not yet for end users. Users sign in with email and their own password, optionally with two-factor authentication. Sign-in with Microsoft Entra ID is on the roadmap. The connection to Power BI itself does run through a Microsoft Entra service principal.
The portal runs on Vercel in the Frankfurt region (fra1). Your organisation's data warehouse is hosted wherever you or your data provider host it; ENABLE connects to it securely and runs only read-only queries.
In an online demo we show you the portal: dashboards per role, row-level security, plain-language questions and how we set it up and manage it for you.