Announcements
Hello everyone;
I created a canvas app and shared it with users. I gave them as security role "basic user" and "system customizer", but the problem is that they have the possibility to view the tables in dataverse and modify and delete them.
What role should I give them so that they can't access the dataverse tables?
@gikido : answered here in the duplicate post in the Power Apps Forum:
https://powerusers.microsoft.com/t5/Building-Power-Apps/Security-role/m-p/2280231#M570345
Hi @gikido ,
System Customizer role should only be for "Makers" of the applications and within the environment will have the ability to update / modify tables, business rules, workflows and the like, I would not assign this role. You should only have to provide them the Basic User role (depending on the tables being used) or normally create a custom role for you specific tables that will provide the appropriate Create / Read / Update / Delete / Share / etc. privileges for your tables (these will not be on the Basic User role by default).
@dpoggemann
Good morning,
I think I did not explain the problem well in the first post, for what I want is to prohibit the users of the application from seeing the tables (see screenshot), and at the application level they can write, view, edit, delete their recordings.
so what should i do to achieve this?
@gikido - why would the suggested answer I gave you in the duplicate post, not answer your question?
@Amik
Hello, sorry I did not pay attention, thank you for your answer, I will try to apply it and see if that solves the problem.
@Amik @dpoggemann
Thanks it works now.
I have a complexity to understand the difference between Organization, Parent: Child Business Unit , Business Unit, User. (For my case I chose organization for all tables).
Can you clarify these concepts for me?
You can find the details on this here.
https://learn.microsoft.com/en-us/power-platform/admin/wp-security-cds#tablerecord-ownership
Basically if you are at "Organization" level in a security role on a table it means the user has that access (i.e. Read) across all business units for that table within the environment. The user would be able to read any record in that table no matter if within the same business unit or any other and if owned by any user.
Subsequently,
@dpoggemann @Amik
and for flows in power automate, do they need a security role so that they are not accessible by users?
Please see the following article for details on flow ownership, licensing requirements and ability to share a flow with others...
https://learn.microsoft.com/en-us/power-automate/create-team-flows
Under review
Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.
Congratulations to our community stars!
Expanding mentorship, skilling, and AI innovation
These are the community rock stars!
Stay up to date on forum activity by subscribing.
WarrenBelz 345 Most Valuable Professional
11manish 207 Super User 2026 Season 2
Mohsin Ali 177