I have a few dozen clients with access to the same dashboard with View only permissions, but with the "Viewer +" Meaning they should be able to create their own scheduled delivery.
However, when I am logged into a test account with "Viewer +" permissions, my only option under Share > Schedule Delivery is to EDIT or DELETE an existing schedule that is not owned by the viewer, but owned by the report owner for a *different client*!
I discovered this because one of my clients added herself to a different client's scheduled send! Thankfully, we have view permissions set up by email address, so the PDF she received was blank / errors. However, I am very concerned that the "can create scheduled send" aka can set up their own scheduled report and own it, is not as advertised and is actually revealing settings and permissions that view only users should not have access to see! This is so concerning!
My only solution for now is to remove all "Viewer +" permissions to simply "Viewer" and let all of my clients know that they have to ask me to set up their scheduled sends on their behalf.
User | Count |
---|---|
1 | |
1 | |
1 | |
1 | |
1 |