Skip to content

Security & Governance

Querri decides who sees what in layers. Roles say what someone can do in the organization. Workspaces decide which work and data a group of people shares. Sharing opens up a single project, dashboard or connector. Access policies go one step further and filter the rows of a table for each person.

You don’t need every layer on day one. A small team might only ever use workspaces and sharing, then add access policies once different people need different slices of the same table.

Querri starts open in two places. Check both before you rely on them.

  • No access policies means full access. Until you create a policy and assign someone to it, everyone sees every row of the data they can open. The Security page says it plainly: “Without policies, all users have full access to all data.”
  • An empty Allowed Domains list means any website can embed Querri. Add your own sites under Embed in Settings to limit it. See Embed Domains.

New projects, dashboards and chats are saved to your private workspace unless you’re working in a workspace you belong to. Work saved in a workspace is visible to its members, according to their role, and a workspace admin can delete or share anything saved there.

Organization admins have one more tool. They can grant anyone, including themselves, access to any project, dashboard, source or connector. Every grant and removal is written to the audit log.

See Workspaces and privacy for where new work lands.

LayerWhat it controlsWho sets itMore
Organization rolesAdmin, Creator or Guest. Admins run Settings, creators build and edit, and guests only view. Invites start as GuestAdmins, in PeoplePeople
WorkspacesWhich work and data a group shares, with Viewer, Creator and Admin rolesAdmins, in WorkspacesWorkspaces
SharingWho can open one project, dashboard, connector or Library item, plus public linksMostly the item’s ownerSharing
Access policiesWhich rows of a table each person seesAdmins, in SecurityAccess Policies
FiltersRows removed from a table for everyone, and filters on a dashboardEditors, owners and adminsFilters
API keysWhat scripts and integrations can do through the APIAdmins, in API KeysAPI Keys
Allowed domainsWhich websites can embed QuerriAdmins, in Embed
Audit logsA record of security changes, and a separate one for billingAdminsAudit Log

Open Settings from your avatar menu. Only admins see these items.

  • Security, in the Security group, with the Access Policies and Audit Log tabs
  • API Keys and Embed, in the same group
  • People and Workspaces, in the Organization group
  • Customize, also under Organization, whose Feature toggles include “Editors can share dashboards”
  • Audit, under Billing & Usage, which is the billing audit log

The Settings overview covers every item in the rail.