> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/manage-user-roles-and-access-management/manage-access-to-objects/manage-access-to-custom-dashboards.md).

# Manage access to custom dashboards

Review the following:

* [Manage access to objects](/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/manage-user-roles-and-access-management/manage-access-to-objects.md)

The **Dashboard Manager** serves as the central repository for your visualizations. By using object-level access, you can ensure that custom (user-defined) dashboards, such as those used for sensitive executive reporting or specialized department views, are only accessible to authorized users and user groups. The permissions assigned to your role, combined with the ownership of specific objects, directly determine the content available to you; you can only access dashboards where you are the Owner, dashboards that have been explicitly shared with you (or your user group), or dashboards marked as **Public**.

{% hint style="warning" %}

### Prerequisite

* **Configure tenant-level settings**: An administrator must first establish the sharing framework under **Settings** → **Configurations** → **Access Management** → **Objects**.

  The configuration of these settings defines the authorized sharing workflows for for all custom objects, including dashboards:

  * **Enable "Owners can Share objects they created"**: Grants owners the ability to share dashboards with specific users and user groups. In the **Dashboard Manager**, this enables the **Share** option.
  * **Disable "Owners can Share objects they created"**: Restricts owners to managing only **General access** (**Public** vs. **Restricted**). In the **Dashboard Manager**, this replaces the **Share** option with the **Manage Access** option.

  For more information on configuring tenant-level settings, see [Manage access to objects](/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/manage-user-roles-and-access-management/manage-access-to-objects.md#how-to-configure-access-to-objects).
* **Define Scope-Based Access Control (SBAC)**: While object-level sharing grants access to the dashboard's layout and configuration, users must also have the appropriate SBAC permissions to view the actual data populated within the widgets. If a user has access to a shared dashboard but lacks the required data scope for the underlying datasets, the dashboard will load, but the widgets may appear empty or display an error. For more information on defining SBAC, see [Manage user scope](/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/manage-user-roles-and-access-management/manage-user-scope.md).
  {% endhint %}

<details>

<summary>Understanding dashboard behavior</summary>

Because dashboards are composed of multiple visualization elements, it is important to understand how access is applied:

* **Dashboard vs. Widget access**: Access to a dashboard is managed through the **Dashboard Manager**. When you share a dashboard, you can also manage access for any **Custom Widgets** contained within it.
* **System Widgets**: Standard system widgets provided by Cortex Cloud remain **Public** and accessible to all users by default; their access cannot be restricted.

</details>

<details>

<summary>Understanding widget behavior</summary>

Because dashboards are composed of multiple widgets, it is important to understand how access is applied to these individual components:

* **Widgets are not objects**: Unlike dashboards, individual widgets are not treated as independent objects. They do not have their own "Share" dialog and cannot be shared independently. Within the Widget Library, a widget is set to either **Restricted** (visible only to the creator) or **Public** (visible to all with Widget Library access).
* **Inherited access**: Any user who has been granted access to a custom dashboard (as a **Viewer** or **Editor**) can see all the widgets contained within that dashboard, including those marked as **Restricted**. This means you may see a widget on a shared dashboard that you cannot see in the Widget Library even if you have access to it.
  * **Dashboard Editors**: Can edit the dashboard layout, but the widget is only available in their Widget Library for editing when the widget is **Public**.
  * **Dashboard Viewers**: Can't make any changes to dashboards or widgets that are **Restricted**.

</details>

<details>

<summary>Change owner of a dashboard</summary>

To ensure continuity when personnel changes occur or to hand off management of a resource, only administrators can change the ownership of a custom dashboard.

{% hint style="info" %}

### Note

Only Account Admins and Instance Administrators have the authority to change the owner of an object.
{% endhint %}

1. Select **Dashboards & Reports** → **Dashboard Manager**.
2. Right-click the custom dashboard in the table and select **Change owner**.
3. Select the new owner from the list of users, and click **Change**.

</details>

<details>

<summary>How to configure access to custom dashboards</summary>

**Step 1: Set role-level permissions**

Role permissions define the functional capabilities for dashboards and the Widget Library, and determine what actions a user can take.

1. Select **Settings** → **Configurations** → **Access Management** → **Roles**.
2. Right-click the relevant user role, and select **Edit Role**.
3. Under **Components**, expand **Dashboards & Reports**, and locate **Dashboards**.
4. Configure access state:
   * **Disabled**: Users cannot navigate to **Dashboards & Reports** → **Dashboard Manager** or **Dashboards & Reports** → **Widget Library**. Dashboards cannot be shared with this role. If the user previously owned or had access to shared dashboards, they are no longer available.
   * **Enabled**: Allows dashboards to be accessed and managed according to defined sub-permissions. Grants access to the Widget Library as explained below in Manage the Widget Library.
5. If **Enabled**, assign specific capabilities to control the UI:
   * **Create Dashboards**: Enables the **New Dashboard** button on the **Dashboard Manager** page, allowing the user to create new custom dashboard objects. The user who performs this action becomes the **Owner** of the object and is granted the inherent right to edit, delete, and manage sharing for that specific object..
   * **Edit Public Dashboards**: Allows the user to modify custom dashboards set to **Public**, even if they are not the owner.
6. Click **Save**.

**Step 2: Manage the widget library**

The Widget Library is the central repository for predefined and custom widgets and is intended for browsing and selecting widgets to add to a dashboard. Access to and visibility within the Widget Library is determined by role-level permissions and your specific access level to the dashboards where those widgets reside:

* **Access to the Widget Library**: To access the Widget Library, your role must have the **Create Dashboards** or **Edit Public Dashboards** capability. Users who only have "View" permissions for dashboards cannot access the Widget Library.
* **Widget Library visibility**: Visibility within the Widget library depends on ownership and inherited dashboard and widget permissions:

  * **Public and personal widgets**: You can always see widgets you created (**Restricted**) and widgets marked as **Public**.
  * **Inherited access via dashboards**: If a **Restricted** widget was created by another user but is part of a dashboard shared with you, you won't see it in the Widget Library and it can't be edited (unless you are an administrator).

  <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>If you're designated as an <strong>Editor</strong>, you can always duplicate the widget and make your changes on the copy.</p></div>

**Step 3: Manage sharing for a custom dashboard**

Once a custom dashboard exists in the Dashboard Manager, the Owner (or an authorized Editor) defines who can see or edit it.

1. Select **Dashboards & Reports** → **Dashboard Manager**.
2. Locate the custom dashboard that you want to share in the table.
3. Right-click the custom dashboard and select the available access option. The menu option you see depends on your tenant-level settings:
   * **Share**: Use this if your admin enabled sharing. It allows you to grant access to specific users/groups and change the **General access** (**Public**/**Restricted**).
   * **Manage Access**: Use this if sharing is disabled. It is a restricted view that only allows you to toggle the **General access** between **Public** and **Restricted**. You cannot grant access to specific individuals.
4. (If sharing is enabled) Search for the **User** or **User Group**, and assign the access level: **Viewer** (read-only) or **Editor** (can modify and share).
5. Set the **General access** state:
   * **Restricted**: Private to the Owner and the others granted access.
   * **Public**: Visible to all users with the **Dashboard** component enabled in their role.
6. Click **Save**.

</details>

<details>

<summary>Sharing icons in the Dashboard Manager</summary>

The following icons help you identify the security access of your custom dashboards:

* ![unshared-query-icon.png](/files/xxJq6a89J4E3AwqWbSty): A **Restricted** custom dashboard you created that is not shared with anyone else.
* ![query-created-by-me-shared-icon.png](/files/In1WCoEExQKBhQUEIuRg): A custom dashboard you created that is currently shared with other users or user groups.
* ![query-created-by-someone-else-shared.png](/files/nMHLbfNdDHFLV1ob7BiN): A custom dashboard created by another user that has been shared with you.
* ![PANW\_Query.png](/files/wz6FZPBNwcaFBcKnTMra): A standard system dashboard provided by Palo Alto Networks. These are always **Public** and cannot be deleted or edited, and their ownership cannot be transferred. Yet, you can **Duplicate** a system dashboard to create a custom version that you can then modify and share.

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-cloud-runtime-security/onboard-and-configure/post-deployment-steps/manage-user-roles-and-access-management/manage-access-to-objects/manage-access-to-custom-dashboards.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
