Unlock a world of possibilities! Login now and discover the exclusive benefits awaiting you.
Hi,
In our Qlik Cloud environment, I noticed that users working with self-service capabilities in a managed space can view and edit application variables.
This only happens when the user is a member of the managed space. When the same user accesses the application through app sharing, without being a member of the space, the variables are not accessible.
I assume this behavior is related to the permissions assigned through the space role.
Which managed-space permission allows users to view or edit variables, and how can I prevent this while still allowing them to use self-service features?
Thx
Hi @sogloqlik
I found the following article in Qlik Help with the permissions to view and edit variables in a Managed Space, under Application actions – Sheets, storytelling, and visualizations.
Managed space permissions for Professional and capacity-based subscription users | Qlik Cloud Help
In relation with the second part of your question, I'm not sure if it can be avoided. I mean, if the users can create sheets, edit objects and so one, I think automatically they will have access to the variables. I discussed this topic for a case I had in support and the answer I had from the developers was that it is working as designed.
Kind Regards
Daniel
I think Daniel's reasoning good. I would recommend all developer variables are managed by the Script - then those variables are protected.
Hi Daniel,
If Qlik Support’s answer is that the system is working as designed in this case, then I find it very puzzling.
According to Qlik’s own definition, managed spaces are intended to contain governed content that users cannot modify, similar to published apps in Qlik Sense on-premises. Allowing users to edit variables therefore seems inconsistent with that principle and is quite concerning.
Moving hundreds of variables into the load script is not a practical solution for us. It would also create additional maintenance and governance difficulties.
I will open a ticket with our local Qlik support team and see what response they provide.