Who sees what? Dashboard permissions across branches and teams
One dashboard everyone sees looks like a simple solution until a branch manager asks why they see another branch's numbers, or an employee stumbles onto salary data. Permissions are not a feature you add but a structure you decide early.
Three levels cover most companies
First: those who see everything, usually one or two people. Second: those who see their own scope, such as a branch manager seeing their branch. Third: those who see aggregated metrics without detail, such as a team tracking the overall target. Most companies try to build ten levels then use only three.
The essential difference: visual hiding versus real prevention
The worst implementation sends all data to the browser then hides some with styling. Anyone opening developer tools sees it all. Real prevention happens on the server or in the database: unauthorized data never leaves its place. Our platform is built this way, with row-level policies in the database rather than in the interface.
Why adding it later costs more
Because permissions touch every query and every screen. Adding them after the build means revisiting everything built, often redesigning the data structure itself. Deciding on day one costs an hour of discussion; deferring costs weeks of rework.
Two questions that settle the design
First: if an employee leaves today, how exactly is their access cut? Second: if someone leaked a screenshot, what is the most dangerous thing on it? These two answers define the required strictness more precisely than any theoretical security discussion.
Frequently asked questions
Do we need a login for every employee?
Yes if data differs by person. A public display dashboard on an office screen does not, provided it carries no sensitive figures.
How do we handle someone needing temporary access?
With a time-limited permission that expires automatically, not by sharing an account. Shared accounts destroy any ability to know who did what, and they are the most common gap we see.
Should we log who opened the dashboard and when?
Yes, and that log serves you twice: it reveals who actually uses the dashboard, and it provides a trail after any leak. Its cost is near zero and its value shows at the first incident.