Concept: Relax Sharing Options
By default, to access the current dataset, you must have access to all upstream datasets and
tables. Example: To share a derived dataset, you must have owner permission on the
derived dataset and at least viewer permission on all upstream datasets and tables.
However, you can relax some permission requirements so that users require
access on fewer upstream datasets and tables to have access to the current dataset.
To relax the sharing restrictions with tables and datasets, Workday provides
these options when you edit dataset sharing and table sharing:
Option Name | Description |
|---|---|
Relax Sharing Rules | When you enable Relax Sharing Rules on a table or dataset:
You can protect sensitive data in upstream datasets and tables by
eliminating the need for access by using Relax Sharing Rules in downstream
datasets. |
Prevent Relax Sharing on Derived Datasets | When you enable Prevent Relax Sharing on Derived Datasets, Workday revokes the Relax
Sharing Rules functionality on all downstream derived datasets. You might want
to enable Prevent Relax Sharing on Derived Datasets to prevent others from
sharing derived datasets they own without requiring your permission on this
table or dataset. The Relax Sharing Rules option is only
functional when no dataset or table upstream from it has Prevent Relax
Sharing Rules on Downstream Datasets enabled. |
To configure these options, you must have access to the
Prism: Manage Relax Sharing
domain in the Prism Analytics functional area.Example: You create a table called Payrolls that contains sensitive data, and you create a
derived dataset off of it called Filtered Payrolls that filters out the sensitive data.
You want Norman Chan to view the Filtered Payrolls dataset, but not the Payrolls table.
To accomplish this sharing scenario, you enable Relax Sharing Rules on Filtered
Payrolls, and then assign Norman Chan viewer permission on it. Now, Norman can view
Filtered Payrolls and create a derived dataset from it even though he doesn’t have
viewer permission on the Payrolls table. Also, he can share the derived dataset he
created without having owner permission on Filtered Payrolls or Payrolls.
To do this... | You must have... |
|---|---|
| At least viewer permission on the current dataset or table, and either:
|
| At least viewer permission on the current dataset, and either:
|
Edit the current dataset or table. | At least editor permission on the current dataset or table, and either:
|
Share the current dataset or table (the action that is specific to owners). | Owner permission on the current dataset or table, and either:
|
View the lineage of the current table or dataset. | At least viewer permission on the current dataset or table. Note that when you view
lineage, you only see the upstream or downstream tables and dataset on which
you have viewer permission (or better). |