> For the complete documentation index, see [llms.txt](https://docs.powermonitor.com.br/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.powermonitor.com.br/en/principais-funcionalidades/permissoes-e-acessos.md).

# Permissions and Access

Consolidated auditing of permissions, external accounts, user activity and report views, for security and LGPD compliance.

Power Monitor consolidates **who has access to what** in your tenant and **what people do** in Power BI and Fabric, for security audits, periodic access reviews and compliance with the **LGPD** (Brazil's General Data Protection Law).

## Who accesses Power Monitor

Access to Power Monitor itself is managed in **Users** (Administrators only):

* **Role and profile:** each person has a **profile** (**Admin**, **Member**, **Audit** or custom) that defines whether they are an **Administrator** or a **User**. Only Administrators configure, trigger collections and manage users.
* **Workspace scope:** limits the data the person sees to certain workspaces and defines which workspaces they receive alert emails from.
* **Page access:** lets you block menu pages for a profile or user. Blocking also applies to the page's data queries (the **Not allowed** screen appears for anyone who opens the address), and Administrators are never blocked.

See the details, the rules of each predefined profile and the step-by-step instructions in [Users](/en/power-monitor/usuarios.md).

## Permissions Audit

In **Audit › Permissions Audit**, you see all permissions granted on **workspaces, Power BI and Fabric items, connections and gateways**:

| Column                               | Meaning                                                                   |
| ------------------------------------ | ------------------------------------------------------------------------- |
| **Object Type** and **Object**       | Where the permission is                                                   |
| **Workspace**                        | The object's workspace                                                    |
| **Principal** and **Principal Type** | Who receives the permission: user, group or application                   |
| **Access Right**                     | The role or permission granted                                            |
| **Source**                           | **Direct**, **Via Group**, **Via Workspace** or **Via Workspace + Group** |

* **Entra ID groups are expanded** down to their members, based on a cache updated with the **Refresh groups** button (requires the Microsoft Graph group read permission, in **Settings › Additional Permissions**).
* Workspace permissions are **propagated to each item** in the workspace, to show the effective access.
* All records that match the filter can be exported to **CSV** or **JSON**.

## Permissions Dashboard

In **Dashboards › Permissions Dashboard**, the aggregated view has the **Overview**, **By person**, **By object**, **Groups** and **External** tabs, with the count of distinct identities (users, groups and applications) and a highlight on **external (guest) accounts**, including those with write access.

## User activity

When activity log collection is enabled (**Settings › Audit**), Power Monitor imports Power BI and Fabric **activity events** three times a day:

* **Audit › Events Overview:** all operations, with date/time, user, operation, item, workspace and status, and indicators such as active users and critical actions;
* **Audit › Report Views:** who viewed each report and dashboard, when and from where (country, state and city estimated from the IP address), including through apps;
* **Dashboards › Report Access Dashboard** (access follows the page access profile: Administrators always, Audit profile enabled, Member blocked by default): most and least active users, most, least and never accessed reports, and distribution by month, workspace, capacity, day of the week and time of day.

## Data exposure

**Data Quality › Data Exposure** and **Governance › Compliance › Public Links** help you find content exposed beyond what is necessary, such as reports published to the web.

## LGPD compliance

* Know exactly **who has access to which data**, including through group and workspace inheritance;
* Identify **external accounts** and unnecessary or excessive access;
* Prove **who accessed** sensitive reports;
* Generate **exports** for internal and regulatory audits.

Access to Power Monitor itself is also recorded in **Audit › Application Events** (logins, pages accessed and configuration changes).

## Related pages

* [Permissions Audit](/en/power-monitor/auditoria/auditoria-de-permissoes.md)
* [Permissions Dashboard](/en/power-monitor/dashboards/dashboard-de-permissoes.md)
* [Events Overview](/en/power-monitor/auditoria/geral-de-eventos.md)
* [Data Exposure](/en/power-monitor/qualidade-de-dados/exposicao-de-dados.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://docs.powermonitor.com.br/en/principais-funcionalidades/permissoes-e-acessos.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `automate deployments from our CI pipeline` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
