It is also possible to use the Access Evaluator App to have a more holistic overview over assignments.
What to remove
To avoid users being promoted to Full Users, remove any assignment, both in single spaces and at a global level.
Spaces
Verify the users are not assigned any roles other than than Has restricted view.
Be careful when using the Anyone group, since assigning any other role to this group will promote all users to Full.
This includes the default data space: Default_Data_Space created on tenant setup. Remove the Anyone member:
Go to Spaces
Click the ellipses menu (...) and choose Manage members
Remove Anyone by through the ellipses menu (...) and clicking Remove
Global
Turn off Auto assign for all Security roles in the Administration Center.
Open the Administration Center
Open Users
Switch to the Permissions tab
Switch Auto assign to Off on all Security roles:
Specific users
If a user was manually assigned a role, the role has to be removed again manually.
Open the Administration Center
Open Users
Switch AllUsers tab if not already selected
Locate the user and click the ... menu (a), then choose Edit roles (b) and remove all previously assigned roles
Remove Custom Group or Groups from Permissions
If a custom or Active Directory group is assigned to a Qlik Cloud permission, you need to remove that group from the permission. Check each permission individually.
Open the Administration Center
Open Manage Users
Switch to the Permissions tab
Locate the role and expand it by clicking the dropdown arrow