Secure Folders

Secure Folders lets you control who can view or edit the dashboards and reports in each company folder. People without access do not see the folder. Secure Folders is available for Emburse Enterprise, Emburse Spend, and Emburse Professional.

Every dashboard and report in a secured folder follows that folder's access. You cannot assign access to one dashboard or report inside a folder. Move content that needs different access into its own folder.

Folder Permissions

Folder permissions are separate from the Viewer and Creator user types. For user types, see Emburse Analytics User Types And Roles.

PermissionWhat it allows
ViewOpen and run dashboards or reports in the folder. The person cannot change the content or the folder permissions.
EditFor a Creator, create, edit, copy, move, or delete content in the folder and manage its permissions.
No accessThe person does not see the folder or its content. Remove the person or group from the permission list to give no access.
  • The Creator user type does not by itself grant Edit access to a Secure Folder.
  • A Creator can have View access on one folder and Edit access on another.
  • A Viewer cannot be granted Edit access.
  • If a person is assigned both directly and through a group, Edit access prevails.

Manage Permissions

Permissions is available to a Creator who has Edit access on that folder. It is always available to Security Admin members. It is not available to a person who has View access only.

  1. Select the folder under the company folder.

  2. From the folder action menu, select Permissions.

  3. Review the people and groups that currently have access. Security Admin has Edit access and cannot be removed from this list.

  4. To restrict the folder, select the trash icon on the All Users row. All Users is the company-wide group. Until you remove that row and select Apply, the folder keeps its existing access.

  5. Select Add to grant access to a named user or a group. For groups, see Group Management Admin Screen.

  6. Select View or Edit for each person or group.

  7. Review the complete permission list, then select Apply.

Select Apply to replace the folder's entire permission list with the list in the dialog. Anyone removed from the list loses access unless a group or Security Admin membership still grants it.

Named User Limit

A folder can have up to 10 directly assigned named users. Groups do not count toward that limit. The counter shows how many named users are selected. At 10 named users, the option to add another named user is disabled until you remove someone. For a larger team, create a reusable group and assign the group instead.

Changes at Enablement

Enabling Secure Folders does not remove access from existing nested folders. Restricting a folder is a separate step.

  • Nested folders keep the access they already had. A Creator who could edit a subfolder can still edit it, rename it, and create content inside it.
  • The only automatic change is at the company root. Users who are not Security Admin members can no longer create folders, dashboards, or reports directly at the first level of the company folder.
  • Security Admin has Edit access across the company folder structure.
  • Removing All Users from one folder does not change any other folder.

Identify the Security Admin members and move content that non-admin Creators must maintain out of the company root.

Security Admin Responsibilities

Each enabled organization has a Security Admin group. Manage its members in Group Management Admin Screen.

  • Security Admin members have Edit access to every folder in the company folder structure.
  • Security Admin members can restore access when a folder's last editor leaves the organization.
  • Security Admin members are the only customer users who can create or manage content directly under the company root after enablement.
  • Nominate at least two active Creators as Security Admin members when possible.

Plan Folder Access

Plan the folder structure before you restrict folders. Parent-folder access can limit what you can set on a child folder.

Edit access granted on a parent folder cannot be reduced to View access on a child folder.

Keep content with different security requirements in separate folders. A practical structure is to leave company-root access at View for All Users, create a folder for each department or purpose, and grant Edit access only where someone maintains the content.

You cannot hide or restrict the Emburse Analytics folder, the Emburse Analytics Pro folder, or personal folders. You can copy standard content into a company folder and secure that copy.

Common Folder Setups

The examples below use Finance Reports as a sample folder.

SetupPermission listWho sees the folder
Open to the companyAll Users with Edit, plus Security Admin with EditEveryone in the company, as before enablement
RestrictedAll Users removed. Named users or groups with View or Edit, plus Security Admin with EditOnly the people you named, the members of the groups you added, and Security Admin members
MixedA group with Edit, All Users with View, plus Security Admin with EditEveryone can view the folder. Only the group and Security Admin members can change its content

Scheduled and Burst Deliveries

Secure Folders does not restrict the data in a scheduled or burst report delivery. A recipient who cannot view the folder can still receive the report output by email.

For example, a Creator with Edit access to Finance Reports can send a scheduled or burst report to people who cannot view that folder. Those recipients still receive the emailed output. To schedule a delivery, see Schedule a Report or Dashboard and Schedule Bursted Reports.

Related Information

Was this article helpful?