Admin, Member, Contributor and Viewer: the four roles, in descending order of privilege, that give access to all items in a workspace.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Workspace roles in context, with comparison tables and the common traps.
Terms in this definition
- Contributor
Built-in Azure role with full management of resources, except that it can't give access to anyone.
- Viewer
Holders can look at workspace content and query data via warehouses or SQL analytics endpoints, yet can't change anything. Semantic model RLS and OLS apply to them. It's the lowest-privilege workspace role.
- ALL
A DAX function that ignores any filters and gives back every row of a table or every value of the named columns. Used within CALCULATE, it works as a modifier that clears filters, although REMOVEFILTERS states that intent more clearly where it is available.
- Workspace
Teams in Power BI and Microsoft Fabric collaborate in this folder-style container, which groups items such as reports, semantic models and lakehouses, controls who can access them and is assigned a capacity.
Related terms
- CONTROL
Granting this on a securable gives all other permissions on it too, making it the most powerful SQL permission. At database scope that includes UNMASK and ALTER ANY MASK. Warehouse access through the Admin, Member or Contributor workspace roles carries it.
- Workspace OneDrive
Links a Power BI workspace to the SharePoint document library of a Microsoft 365 group so files can be stored there. Workspace roles and group membership aren't kept in sync by Power BI.