Version v0.42 of Metabase is no longer supported. Check out the docs for the current stable version, Metabase v0.63.
This troubleshooting guide has you covered if you’ve connected your database to Metabase, set up groups for new people, and granted data permissions and collection permissions to those groups, but:
Root cause: This person is a member of multiple groups, in which case Metabase grants the most permissive level of access across all the groups in which they’re a member.
If they’re a member of two groups — one which grants Unrestricted access to a database or table and another that grants No self-service access — that person will have full unrestricted access.
Steps to take:
Remember that everyone is a member of the All Users group; this is why we recommend you revoke permissions from the All users group, and create new groups to selectively apply permissions to your data sources.
Root cause: The person currently has either No self-service or Granular access to a database. To give someone access to the native SQL editor, you must grant Unrestricted access to the database as a whole.
Steps to take:
This feature is only available on Pro and Enterprise plans (both self-hosted and on Metabase Cloud).
Root cause: Since Metabase operates with two types of permissions — data permissions and collection permissions — even if you’ve granted a user group no self-service access to a database or table, they can still view saved questions and dashboards that draw on that database, as long as those questions and dashboards live in a collection they have access to. Unless a user group’s access to a given database is set to “block,“ they’ll be able to view any saved question based on that data if they have access to the collection it’s saved in.
Steps to take:
Keep in mind that if a person belongs to another group that does have data access, that setting will take precedence, and their access will not be blocked.