Who Can See a Recipe or Dashboard
Access to a Recipe or a Dashboard is controlled by two independent layers:
- Role permissions decide which features a user can use.
- Share settings decide which specific objects a user can see.
Both layers have to line up. Giving someone a role that contains every permission in the product does not make existing recipes or dashboards appear for them. This is the most common source of confusion around access, and it is working as designed.
If a user can open the Recipes section but the list is empty, the problem is almost never their role. It is that no recipe has been shared with them.
What a role permission actually grants
A role permission grants access to a product area — the ability to open a section, and to create, edit, or delete objects that the user can already see.
A role permission does not grant visibility into objects that already exist.
For recipes this is absolute: role permissions are not consulted at all when deciding whether a user can see a recipe. The only role that changes recipe visibility is Workspace Admin. Separately, whoever created a recipe can always see it — but that is ownership of the object, not a role.
For dashboards the two layers do interact — a workspace-visible dashboard still requires the user's role to carry the dashboard view permission. See Who can see a Dashboard below.
For what each role contains, see Available User Roles and Custom Roles & Permissions.
The Share permission listed in the role permission tables refers to sharing an AI Agent chat. It does not control Recipe or Dashboard sharing, which is set on each object individually.
Recipe sharing
Open a Recipe and select Share.
A recipe's access is made up of two kinds of entry:
- Workspace access — a single entry covering everyone in the workspace. In the dialog this row is labelled with your workspace's name, for example Main Group.
- Individual users — any number of per-person entries.
Available permissions
| Permission | Effect |
|---|---|
| Restricted | No access from this entry |
| Read | Can open and view the recipe |
| Edit | Can view, modify, and change the recipe's Share settings |
There is no option to share a recipe with a team. Sharing targets are individual users or the whole workspace. The row named after your workspace is workspace-wide access — it is not a team.
Default when a recipe is created
A new recipe is Restricted. Until someone changes its Share settings, only its owner and Workspace Admins can see it.
Who can change a recipe's Share settings
Anyone with Edit access to the recipe: its owner, a Workspace Admin, anyone granted Edit directly or through workspace access, or anyone with Edit on a folder that contains it. You cannot change your own permission on a recipe.
Access through folders
A recipe can also become visible through the folder it sits in. If a folder is shared with Read or Edit, that access flows through to the recipes inside it. If someone can see a recipe you never shared with them directly, check the folder.
Dashboard sharing
Open a Dashboard and select Share in the upper-right corner.
A dashboard has one General access mode, plus a list of invited people.
General access
| Mode | Effect |
|---|---|
| Workspace | Everyone in the workspace whose role carries the dashboard view permission can see it |
| Restricted | Only the owner and explicitly invited people can see it |
As with recipes, the General access row is labelled with your workspace's name, for example Main Group, and represents workspace-wide access rather than a team.
Invited people
| Level | What the user can do |
|---|---|
| View | Open and view the dashboard |
| Edit | View and modify the dashboard |
| Edit & Share | View and modify the dashboard, invite other people, and enable or disable the public link |
The dashboard's creator is shown as Owner. Owner is a label for the creator, not a level you can grant.
Default when a dashboard is created
A new dashboard is Workspace. It is visible to the workspace from the moment it is created.
Who can change dashboard sharing
- General access mode — the owner only. Edit & Share users cannot change it.
- Invites and the public link — the owner, Edit & Share users, and any user whose role carries the dashboard edit permission on a workspace-mode dashboard.
Public link
A dashboard can also be published as a public link, which grants view-only access without an Improvado account. Each link is scoped to a single dashboard. The public link is independent of the General access mode — a Restricted dashboard can still have one. See AI Dashboards for the full public-link behaviour.
The defaults are opposite
| Object | Default when created |
|---|---|
| New recipe | Restricted — private until it is shared |
| New dashboard | Workspace — visible to the workspace immediately |
Same Share button, same workspace row, opposite starting behaviour. A team that builds dashboards first will find that sharing "just works", then hit a wall on recipes and reasonably conclude something is wrong with their roles. Nothing is wrong — recipes start private and dashboards do not.
Who can see a Recipe
| Viewer | Workspace access = Restricted | Workspace access = Read or Edit |
|---|---|---|
| Owner | Visible | Visible |
| Workspace Admin | Visible — bypasses sharing | Visible |
| Any other role, including a custom role with every permission | Not visible | Visible |
| A user shared on the recipe directly | Visible | Visible |
| A user with access to the recipe's folder | Visible | Visible |
Workspace Admins see every recipe in the workspace regardless of its Share settings. This bypass is tied specifically to the Workspace Admin role — no other role has it, no matter how many permissions it carries. The Owner row above refers to the person who created the recipe, which is a property of the recipe rather than a role.
Who can see a Dashboard
| Viewer | General access = Restricted | General access = Workspace |
|---|---|---|
| Owner | Visible | Visible |
| Invited user (View, Edit, or Edit & Share) | Visible | Visible |
| Workspace Admin who is not the owner and not invited | Not visible | Visible, if their role carries the dashboard view permission |
| Any other role, not invited | Not visible | Visible, if their role carries the dashboard view permission |
| Someone holding the public link | Visible, view-only | Visible, view-only |
Dashboards behave differently from recipes in two ways. Workspace Admins do not automatically see restricted dashboards. And in Workspace mode the user's role permission is still required — this is the one place where the two layers combine.
Common pitfall
A workspace invites several new users and gives them the Editor role. They can open the Recipes section, but the list is empty. The team tries a custom role with every permission except user management. Still empty. Granting Workspace Admin makes the recipes appear, so the team leaves those users as Workspace Admins.
What actually happened. The recipes were Restricted. No role change could have fixed that, because recipe visibility does not consult role permissions. Workspace Admin worked only because it is the one role that bypasses sharing — which also handed those users control over billing, workspace members, and every connection in the workspace.
The correct fix. Open each recipe's Share dialog and either set workspace access to Read or Edit, or add the specific users. Then return the over-granted users to their intended role. If the recipes are organised in folders, sharing the folder covers everything inside it in one step.
Checking what a resource is currently shared with
Sharing status is not shown in either list view:
- The Recipes list shows Name, Data Table, Status, and Updated At.
- The Dashboards list shows Name, Created by, Tags, and Date.
Neither list shows whether an item is Restricted, workspace-visible, or public. To check, open the item and select Share.
Was this article helpful?
Thanks for the feedback!