Skip to main content

Data permissions

Last updated 06/25/2026

Data permissions control the data that members can access in a project, enabling row-level and column-level data control.

Data permission control consists of the following three parts:

  • Visibility settings: Set whether events, event properties, or user properties are visible. This applies to scenarios where users shouldn't view data such as cost data or attribution data.
  • Data range: Filter the available data range based on property rules so that only data meeting the filter conditions can be accessed. This applies to scenarios such as distinguishing data sources or viewing data by channel.
  • Data desensitization: Mask sensitive properties in drill-down event or user lists and in user behavior sequences to meet compliance requirements for masking detailed data.

Because data permissions differ, different members may see different results when viewing the same dashboard or report. Members can check their data permissions in the current project in Personal Center.

Visibility settings​

You can set which events, event properties, or user properties are visible. Only the selected events or properties can be used in analysis or have their analysis results viewed, including:

  • The events or properties that can be selected when querying
  • Whether reports shared by others can be viewed normally (if a report uses invisible events or properties, a message indicates that you don't have view permission)

On the left of the settings bar, you can set whether new events or properties are visible by default. The default is Keep all new events visible (or Keep all new event properties visible), which means that after visibility permissions are set, new events or properties stored in the database are viewable by default.

To control the visibility of new events or properties, turn off this option. After it's turned off, users with this data permission cannot use new events or properties in the project by default.

For example, suppose fields such as cost and attribution are reported in user properties, and a member of the project shouldn't have view permission for these properties. Create a data permission, set these properties as invisible in the visibility settings, and assign the data permission to that member.

Data range​

You can limit the data range that members can access in a project based on event properties or user properties. After this is set, members can only access the data range that meets the filter conditions, including:

  • The data range of calculation results when querying
  • The data range of calculation results when viewing reports shared by others

How the data range takes effect depends on the type of property that is set:

Filter propertyData rangeExample
Event propertiesOnly event data that meets the filter conditions can be accessedFor example, if you filter by event property [Server ID=1], only event data whose Server ID is 1 can be accessed
User propertyOnly users that meet the filter conditions and their event data can be accessedFor example, if you filter by user property [Source Channel=Huawei AppGallery], only users from Huawei AppGallery and the event data generated by these users can be accessed

Common scenarios:

  • For joint operation businesses, such as publishing a game through multiple third parties, you may want the publisher of channel A to view only the user data under channel A. Create a data permission, set a user filter, such as (Source Channel=A), and assign the data permission to the publisher's members to isolate the data.
  • For a new member, an admin may want to open up data access gradually, for example, only for the last 30 days. Set an event filter (Event Time is between -30 days and 0 days relative to the current date) to control the data query range.

Data desensitization​

You can select the event property and user property fields to desensitize. Desensitized fields apply only to detailed information, including drill-down lists (event lists and user lists) and user behavior sequences. The selected desensitized fields are masked with special characters (*).

Delete a data permission​

When you delete a data permission that still has members, you can move these members to another data permission.

Special rules for tag creation and Metric Alerts​

To ensure availability for different members, data permissions follow special rules in the tag creation process and in Metric Alerts:

  • Tag creation: For members with different data permissions, tags are always calculated with "all data" permissions, and data permissions are applied only when each member views the tag calculation results. For example, if member a's data permission in project A is [Can access only user data whose source channel is Huawei AppGallery], the tag values are calculated with the full data when member a creates a tag. However, when member a views tag details or views tag data on a dashboard, member a can only view the tag data and details of users whose source channel is Huawei AppGallery.
  • Metric Alerts: Because the creator needs to create alert trigger rules based on how the metric performs, the calculation range of alert data is consistent with the creator's data permissions. When you create an alert in Metric Alerts, the creator's data range conditions are applied automatically.
Was this page helpful?