Skip to main content
When you add a Dashboard or other content brought in from connected integrations like Tableau, Curator will inherit the security settings from those integrations. However, you may want to override those source-systems or you may want to prevent users from seeing content that exists solely within Curator - for example, restricting access to a specific page. With Restrict Access you can override inherited security settings when necessary, offering you maximum flexibility over the visibility of content.

Enabling Restrict Access

  1. On the backend of Curator, navigate to the Content > Reorder Navigation section from the left-hand menu.
  2. Find the menu link you’d like to restrict access to and click the pencil/edit icon - or click the “New Menu Link” button to create a new menu item.
  3. Toggle the Restrict Access to ON to display a list of groups
  4. Select the groups you’d like to grant access to
  5. Save the menu item
You can then confirm the restrict access is enabled on the Reorder Navigation page by hovering over the lock icon and seeing the phrase “Restricted Access based on Group Membership” Tableau admins automatically have access to all Tableau-connected content in Curator. Restrict access overrides these permissions, so admins will need to be in one of the selected groups to see the content within the menu. Restrict Access is enforced on every page load, not just when rendering navigation menus. This means that if a user shares a Curator URL with someone who is not in an authorized group, that person will still be blocked from viewing the content. There is no additional configuration required to protect against unauthorized access via shared or bookmarked URLs — the same group-membership check applies regardless of how the page is reached.

Restrict Access and Tableau Connection Issues

Inherited Tableau permissions can only be checked while Curator is able to reach Tableau Server. If the connection is down, disabled, or misconfigured when a user requests a dashboard, Curator cannot verify that user’s Tableau permissions and grants access instead of blocking it, so that a temporary outage does not lock out users who are otherwise entitled to the content. This result can be cached for up to 24 hours, which means access may stay open for a while even after the connection to Tableau Server is restored. Restrict Access is a separate check that reads only from Curator’s own database, so it is unaffected by Tableau connectivity. Because of this, Restrict Access is not redundant with inherited Tableau permissions — it is the only access control on a menu item that keeps working while the Tableau connection is unavailable. Enable Restrict Access directly on any menu item whose content must stay protected even during a Tableau outage. To apply this protection everywhere at once, enable Settings > Security > Authentication Settings > Customization > Restrict Access is Always Enabled, which treats every menu item as restricted and requires each one to list the groups allowed to see it. See Frontend User Permissions for details on that setting.
The global Restrict Access is Always Enabled setting only evaluates content that is linked from at least one menu item. A dashboard with no menu link has nothing to restrict, so it skips this check and its access still depends solely on the Tableau connection. Add a menu link for any content that must remain protected during an outage.