dosubot[bot] commented on issue #35795: URL: https://github.com/apache/superset/issues/35795#issuecomment-3432152250
<!-- Answer --> The permissions all_datasource_access and all_database_access grant broad access to all data sources and databases in Superset, and they include both read and write capabilities—not just read-only access. These permissions are assigned to the Admin and Alpha roles, which can view, create, edit, and delete datasets, charts, dashboards, and databases. For example, Alpha users can add and alter data sources, confirming that these permissions allow write actions as well as read actions [docs](https://github.com/apache/superset/blob/master/docs/docs/security/security.mdx) [permission matrix](https://github.com/apache/superset/blob/master/RESOURCES/STANDARD_ROLES.md). If you want a strictly read-only role, you should avoid granting these global permissions and instead assign only the specific can_read (or can_list/can_show) permissions for each asset type. <!-- Dosu Comment Footer --> *To reply, just mention [@dosu](https://go.dosu.dev/dosubot).* --- <sup>How did I do? [Good](https://app.dosu.dev/response-feedback/6554ed6b-ea8f-4136-97dd-d038736db2d3?feedback_type=great_response) | [Irrelevant](https://app.dosu.dev/response-feedback/6554ed6b-ea8f-4136-97dd-d038736db2d3?feedback_type=irrelevant_answer) | [Incorrect](https://app.dosu.dev/response-feedback/6554ed6b-ea8f-4136-97dd-d038736db2d3?feedback_type=incorrect_sources) | [Verbose](https://app.dosu.dev/response-feedback/6554ed6b-ea8f-4136-97dd-d038736db2d3?feedback_type=too_verbose) | [Hallucination](https://app.dosu.dev/response-feedback/6554ed6b-ea8f-4136-97dd-d038736db2d3?feedback_type=hallucination) | [Report 🐛](https://app.dosu.dev/response-feedback/6554ed6b-ea8f-4136-97dd-d038736db2d3?feedback_type=bug_report) | [Other](https://app.dosu.dev/response-feedback/6554ed6b-ea8f-4136-97dd-d038736db2d3?feedback_type=other)</sup> [](https://app.dosu.dev/a28d3c7e-a9d3-459e-9fb6-3a6f9ff4f357/ask?utm_source=githu b) [](https://go.dosu.dev/discord-bot) [](https://twitter.com/intent/tweet?text=%40dosu_ai%20helped%20me%20solve%20this%20issue!&url=https%3A//github.com/apache/superset/issues/35795) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
