Manage security in planning

Use Security in the planning sheet to control access to planning sheets and planning features by assigning users to one or more security roles.

  • You can create multiple roles with different permission levels and assign one or more roles to each user.
  • Configure security settings at the sheet level and for the planning features such as Measures, Scenario, Writeback, and Comments.

In this article, you learn how to create and manage roles, set sheet-level and feature-level permissions for each role, and assign users to different roles.

To open the Security window, select Security from the toolbar.

It consists of two sections:

  • Users - Use this section to assign one or more roles to users.
  • Roles - Select this section to create and configure security roles.

Create and manage roles#

Security roles define the permissions available to a group of users. Create multiple roles to provide different levels of access based on user responsibilities. After creating a role, assign it to one or more users.

The Item Baseline role is created by default and applies to all users. You can configure common permissions in this role or create additional roles to provide different access levels for different groups of users.

Create a role

To create a role:

  1. In the Security window, select Roles.
  2. Select Add Roles.
  3. Enter a role name, and then select Add.

  4. Configure the required permissions for the role.
  5. Select Save Changes.

After the role is created, assign it to users from the Users page.

Edit a role

To rename a role:

  1. In the Roles page, select the role that you want to edit.
  2. Select the Edit icon.
  3. Enter a new role name, and then select Save.

Renaming a role updates only its name. The configured permissions remain unchanged.

Delete a role

To delete a role:

  1. In the Roles page, select the role that you want to delete.
  2. Select the Delete icon.
  3. Confirm the deletion.

The Item Baseline role is the default system role and cannot be renamed or deleted.

Configure general permissions#

The General tab controls access to planning sheets for the selected role. All sheets available in the item are listed individually, allowing you to configure visibility and editing permissions for each sheet.

Select the role on the left. Then, for every sheet, set the following permissions:

PermissionDescription
VisibleDetermines whether the sheet is visible to users assigned to the selected role. Disable this option to hide the sheet from users.
Read OnlyAllows users to view the sheet but prevents them from making changes. Disable this option to allow users to edit the sheet.

By default, you can view and edit all sheets for the selected role. You can configure individual sheets to hide them or make them read-only as required.

Enable the Visible toggle to make the sheet available to users. If you disable the Visible toggle, users can't access the sheet regardless of the Read Only setting.

Configure planning permissions#

The Planning tab lets you configure permissions for planning-specific features. You can apply permissions to All Sheets or Specific Sheets.

  • All Sheets - Applies the configured permissions to all planning sheets.
  • Specific Sheets - Applies the configured permissions only to the selected sheets.

To configure permissions for specific sheets:

  1. Select Specific Sheets.
  2. Select Select Sheets.
  3. Select one or more sheets from the list.
  • Only sheets that contain the corresponding Planning feature are available for selection.
  • Any sheet that isn't explicitly configured under Specific Sheets defaults to Read + Write access.

The Planning tab lets you configure permissions for the following features:

  • Measures
  • Data Input & Forecast
  • Scenario
  • Writeback
  • Comments

Measures

Configure permissions for accessing and modifying data input and forecast measures.

Available permissions:

PermissionDescription
HiddenHides the measures from users assigned to the selected role.
ReadAllows users to view measures but prevents them from making changes.
Read + WriteAllows users to view and modify measures.

Scenario

Configure whether users can access and work on Planning scenarios.

PermissionDescription
ViewAllows users to view and work with scenarios. Clear this option to prevent users from accessing scenarios.

Writeback

Configure whether users can perform writeback operations.

PermissionDescription
WritebackAllows users to write planning changes back to the data source. Clear this option to prevent writeback operations.

Comments

Configure permissions for comments.

Available permissions:

PermissionDescription
ViewAllows users to view comments.
AddAllows users to add comments.
Lock/UnlockAllows users to lock or unlock comments.
StarAllows users to mark comments as starred.

You can enable or disable each permission independently.

Assign users to roles#

After configuring one or more roles, assign them to users to control their access to planning sheets and features.

To assign roles to users:

  1. In the Security window, select Users.
  2. Select Assign Role.
  3. In the Users dropdown, select one or more users.
  4. In the Roles dropdown, select one or more roles.
  5. Select Add.

A user can be assigned to multiple roles.

Permission precedence

When a user is assigned multiple roles, permissions from all assigned roles are considered. If different roles define different permission levels for the same feature, the highest level of access is granted.

Example

Consider the configured permissions for the Member and Lead roles in the planning security settings.

FeatureMemberLead
MeasuresRead + WriteRead
ScenarioViewView
WritebackNoYes
CommentsView, AddView, Add, Lock/Unlock, Star Comments

Suppose a user is assigned both the Member and Lead security roles.

The effective permissions for the user are as follows:

FeatureEffective permission
MeasuresRead + Write
ScenarioView
WritebackYes
CommentsView, Add, Lock/Unlock, Star Comments

The user receives Read + Write access to Measures from the Member role and Writeback and advanced Comments permissions from the Lead role. Because permissions from all assigned roles are considered, the user receives the highest level of access available for each feature.

Return to the Planning sheet#

After configuring users and roles, select Back to Sheet to return to the Planning sheet.

Fabric Plan
Enterprise planning, Integrated with PowerTable and Intelligence, native to Microsoft Fabric. Co Engineered with Lumel.
BUILT ON