Security & Governance
Esta página aún no está disponible en español. Se muestra la versión en inglés.
Querri decides who sees what in layers. Roles say what someone can do in the organization. Workspaces decide which work and data a group of people shares. Sharing opens up a single project, dashboard or connector. Access policies go one step further and filter the rows of a table for each person.
You don’t need every layer on day one. A small team might only ever use workspaces and sharing, then add access policies once different people need different slices of the same table.
Two defaults to know
Section titled “Two defaults to know”Querri starts open in two places. Check both before you rely on them.
- No access policies means full access. Until you create a policy and assign someone to it, everyone sees every row of the data they can open. The Security page says it plainly: “Without policies, all users have full access to all data.”
- An empty Allowed Domains list means any website can embed Querri. Add your own sites under Embed in Settings to limit it. See Embed Domains.
Private until you share it, mostly
Section titled “Private until you share it, mostly”New projects, dashboards and chats are saved to your private workspace unless you’re working in a workspace you belong to. Work saved in a workspace is visible to its members, according to their role, and a workspace admin can delete or share anything saved there.
Organization admins have one more tool. They can grant anyone, including themselves, access to any project, dashboard, source or connector. Every grant and removal is written to the audit log.
See Workspaces and privacy for where new work lands.
The layers
Section titled “The layers”| Layer | What it controls | Who sets it | More |
|---|---|---|---|
| Organization roles | Admin, Creator or Guest. Admins run Settings, creators build and edit, and guests only view. Invites start as Guest | Admins, in People | People |
| Workspaces | Which work and data a group shares, with Viewer, Creator and Admin roles | Admins, in Workspaces | Workspaces |
| Sharing | Who can open one project, dashboard, connector or Library item, plus public links | Mostly the item’s owner | Sharing |
| Access policies | Which rows of a table each person sees | Admins, in Security | Access Policies |
| Filters | Rows removed from a table for everyone, and filters on a dashboard | Editors, owners and admins | Filters |
| API keys | What scripts and integrations can do through the API | Admins, in API Keys | API Keys |
| Allowed domains | Which websites can embed Querri | Admins, in Embed | |
| Audit logs | A record of security changes, and a separate one for billing | Admins | Audit Log |
Where the settings are
Section titled “Where the settings are”Open Settings from your avatar menu. Only admins see these items.
- Security, in the Security group, with the Access Policies and Audit Log tabs
- API Keys and Embed, in the same group
- People and Workspaces, in the Organization group
- Customize, also under Organization, whose Feature toggles include “Editors can share dashboards”
- Audit, under Billing & Usage, which is the billing audit log
The Settings overview covers every item in the rail.
What’s in this section
Section titled “What’s in this section”- Governing Access: who owns data, and where admins keep control
- Sharing: share dialogs, roles and public links
- Access Policies: row-level security
- API Keys: keys for scripts, integrations and embeds
- Dashboard Security: what each dashboard viewer sees
- Filters: source filters and dashboard filters
- Workspaces: roles and membership
- Audit Log: what’s recorded, and how to read it