> For the complete documentation index, see [llms.txt](https://docs.fabricplan.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.fabricplan.com/planning-sheets/how-tos/manage-security-in-planning.md).

# Manage security in planning

Use **Security** in the planning sheet to control access to planning sheets and planning features by assigning users to one or more security roles.

* You can create multiple roles with different permission levels and assign one or more roles to each user.
* Configure security settings at the sheet level and for the planning features such as **Measures**, **Scenario**, **Writeback**, and **Comments**.

In this article, you learn how to create and manage roles, set sheet-level and feature-level permissions for each role, and assign users to different roles.

To open the Security window, select **Security** from the toolbar.

<figure><img src="https://257222532-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUtolck8kt8atqxFPsEBn%2Fuploads%2FY9FSlrnJ0DyrWSdzHcQE%2Fimage.png?alt=media&amp;token=1c308e77-d648-405e-944e-229a41e5ac54" alt=""><figcaption></figcaption></figure>

It consists of two sections:

* **Users** - Use this section to assign one or more roles to users.
* **Roles** - Select this section to create and configure security roles.

<figure><img src="https://257222532-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUtolck8kt8atqxFPsEBn%2Fuploads%2FPLCKEieKZSnk9ARDUpnB%2Fimage.png?alt=media&amp;token=c37f7559-d55b-4baf-bafa-3d84cef87f25" alt=""><figcaption></figcaption></figure>

### Create and manage roles

Security roles define the permissions available to a group of users. Create multiple roles to provide different levels of access based on user responsibilities. After creating a role, assign it to one or more users.

{% hint style="info" %}

#### Note

The **Item Baseline** role is created by default and applies to all users. You can configure common permissions in this role or create additional roles to provide different access levels for different groups of users.
{% endhint %}

#### Create a role

To create a role:

1. In the **Security** window, select **Roles**.
2. Select **Add Roles**.
3. Enter a role name, and then select **Add**.<br>

   <figure><img src="https://257222532-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUtolck8kt8atqxFPsEBn%2Fuploads%2FnJhx37JiWD0KnYUBxi1j%2Fimage.png?alt=media&amp;token=98f41eab-bcb0-4dac-9ade-08018b2e691d" alt=""><figcaption></figcaption></figure>
4. Configure the required permissions for the role.
5. Select **Save Changes**.

After the role is created, assign it to users from the **Users** page.

#### Edit a role

To rename a role:

1. In the **Roles** page, select the role that you want to edit.
2. Select the **Edit** icon.
3. Enter a new role name, and then select **Save**.

{% hint style="info" %}

#### Note

Renaming a role updates only its name. The configured permissions remain unchanged.
{% endhint %}

#### Delete a role

To delete a role:

1. In the **Roles** page, select the role that you want to delete.
2. Select the **Delete** icon.
3. Confirm the deletion.

<figure><img src="https://257222532-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUtolck8kt8atqxFPsEBn%2Fuploads%2FzTQjclxQa0NP8TXU82FJ%2Fimage.png?alt=media&amp;token=3a18ff8c-0fda-41c6-8a79-9dbd648ad832" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}

#### Note

The **Item Baseline** role is the default system role and cannot be renamed or deleted.
{% endhint %}

### Configure general permissions

The **General** tab controls access to planning sheets for the selected role. All sheets available in the item are listed individually, allowing you to configure visibility and editing permissions for each sheet.

<figure><img src="https://257222532-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUtolck8kt8atqxFPsEBn%2Fuploads%2FnIrHwZZVtPFIfnCnD9U3%2Fimage.png?alt=media&amp;token=751c87d5-a50e-448b-9e5f-38103593916f" alt=""><figcaption></figcaption></figure>

Select the role on the left. Then, for every sheet, set the following permissions:

<table><thead><tr><th width="132.18182373046875">Permission</th><th>Description</th></tr></thead><tbody><tr><td><strong>Visible</strong></td><td>Determines whether the sheet is visible to users assigned to the selected role. Disable this option to hide the sheet from users.</td></tr><tr><td><strong>Read Only</strong></td><td>Allows users to view the sheet but prevents them from making changes. Disable this option to allow users to edit the sheet.</td></tr></tbody></table>

By default, you can view and edit all sheets for the selected role. You can configure individual sheets to hide them or make them read-only as required.

{% hint style="info" %}

#### Important

Enable the **Visible** toggle to make the sheet available to users. If you disable the **Visible** toggle, users can't access the sheet regardless of the **Read Only** setting.
{% endhint %}

### Configure planning permissions

The **Planning** tab lets you configure permissions for planning-specific features. You can apply permissions to **All Sheets** or **Specific Sheets**.

* **All Sheets** - Applies the configured permissions to all planning sheets.
* **Specific Sheets** - Applies the configured permissions only to the selected sheets.

To configure permissions for specific sheets:

1. Select **Specific Sheets**.
2. Select **Select Sheets**.
3. Select one or more sheets from the list.

{% hint style="info" %}

#### Note

* Only sheets that contain the corresponding Planning feature are available for selection.
* Any sheet that isn't explicitly configured under **Specific Sheets** defaults to **Read + Write** access.
  {% endhint %}

The **Planning** tab lets you configure permissions for the following features:

* **Measures**
* **Data Input & Forecast**
* **Scenario**
* **Writeback**
* **Comments**

<figure><img src="https://257222532-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUtolck8kt8atqxFPsEBn%2Fuploads%2F0vgiudmF2HvJuEQXVvsk%2Fimage.png?alt=media&amp;token=d7ab719a-cb5b-4d88-bddd-87faf04d79ea" alt=""><figcaption></figcaption></figure>

#### Measures

Configure permissions for accessing and modifying data input and forecast measures.

Available permissions:

<table><thead><tr><th width="179.90911865234375">Permission</th><th>Description</th></tr></thead><tbody><tr><td><strong>Hidden</strong></td><td>Hides the measures from users assigned to the selected role.</td></tr><tr><td><strong>Read</strong></td><td>Allows users to view measures but prevents them from making changes.</td></tr><tr><td><strong>Read + Write</strong></td><td>Allows users to view and modify measures.</td></tr></tbody></table>

#### Scenario

Configure whether users can access and work on Planning scenarios.

<table><thead><tr><th width="190.3636474609375">Permission</th><th>Description</th></tr></thead><tbody><tr><td><strong>View</strong></td><td>Allows users to view and work with scenarios. Clear this option to prevent users from accessing scenarios.</td></tr></tbody></table>

#### Writeback

Configure whether users can perform writeback operations.

<table><thead><tr><th width="197.18182373046875">Permission</th><th>Description</th></tr></thead><tbody><tr><td><strong>Writeback</strong></td><td>Allows users to write planning changes back to the data source. Clear this option to prevent writeback operations.</td></tr></tbody></table>

#### Comments

Configure permissions for comments.

Available permissions:

<table><thead><tr><th width="203.54547119140625">Permission</th><th>Description</th></tr></thead><tbody><tr><td><strong>View</strong></td><td>Allows users to view comments.</td></tr><tr><td><strong>Add</strong></td><td>Allows users to add comments.</td></tr><tr><td><strong>Lock/Unlock</strong></td><td>Allows users to lock or unlock comments.</td></tr><tr><td><strong>Star</strong></td><td>Allows users to mark comments as starred.</td></tr></tbody></table>

You can enable or disable each permission independently.

### Assign users to roles

After configuring one or more roles, assign them to users to control their access to planning sheets and features.

To assign roles to users:

1. In the **Security** window, select **Users**.
2. Select **Assign Role**.
3. In the **Users** dropdown, select one or more users.
4. In the **Roles** dropdown, select one or more roles.
5. Select **Add**.

A user can be assigned to multiple roles.

<figure><img src="https://257222532-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FUtolck8kt8atqxFPsEBn%2Fuploads%2FBDC9bgCiNN7H3Hgpwcon%2FGemini_Generated_Image_9083pm9083pm9083.png?alt=media&amp;token=7582634f-1fe7-4331-b226-bdfd25e6d376" alt=""><figcaption></figcaption></figure>

#### Permission precedence

When a user is assigned multiple roles, permissions from all assigned roles are considered. If different roles define different permission levels for the same feature, the highest level of access is granted.

#### Example

Consider the configured permissions for the Member and Lead roles in the planning security settings.

<table><thead><tr><th width="152.18182373046875">Feature</th><th>Member</th><th>Lead</th></tr></thead><tbody><tr><td><strong>Measures</strong></td><td>Read + Write</td><td>Read</td></tr><tr><td><strong>Scenario</strong></td><td>View</td><td>View</td></tr><tr><td><strong>Writeback</strong></td><td>No</td><td>Yes</td></tr><tr><td><strong>Comments</strong></td><td>View, Add</td><td>View, Add, Lock/Unlock, Star Comments</td></tr></tbody></table>

Suppose a user is assigned both the **Member** and **Lead** security roles.

The effective permissions for the user are as follows:

<table><thead><tr><th width="168.90911865234375">Feature</th><th>Effective permission</th></tr></thead><tbody><tr><td><strong>Measures</strong></td><td>Read + Write</td></tr><tr><td><strong>Scenario</strong></td><td>View</td></tr><tr><td><strong>Writeback</strong></td><td>Yes</td></tr><tr><td><strong>Comments</strong></td><td>View, Add, Lock/Unlock, Star Comments</td></tr></tbody></table>

The user receives **Read + Write** access to **Measures** from the **Member** role and **Writeback** and advanced **Comments** permissions from the **Lead** role. Because permissions from all assigned roles are considered, the user receives the highest level of access available for each feature.

### Return to the Planning sheet

After configuring users and roles, select **Back to Sheet** to return to the Planning sheet.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.fabricplan.com/planning-sheets/how-tos/manage-security-in-planning.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
