Providing you are a LUSID user with sufficient privileges, you can create a policy to grant or restrict access to one or more workspaces in LUSID.
Note: If you are the LUSID domain owner, you are automatically assigned the built-in
lusid-administratorrole, which has all the permissions necessary to perform the operations in this article.
Once created, you should assign the policy to a role.
Administrative access to workspaces
To create a policy that grants access to create, edit, and delete a workspace, and create and delete items within that workspace:
Navigate to Identity and Access > Policies and click the Create policy button.
.png?sv=2022-11-02&spr=https&st=2026-02-12T11%3A52%3A26Z&se=2026-02-12T12%3A03%3A26Z&sr=c&sp=r&sig=6l58HcWpAY9uzyGnAx6WUbE9mFRPvqzLV52kYA7x82I%3D)
Specify the following:
A unique Policy code
A friendly Description for the policy
Whether this policy will Allow or Deny access to the specified features and data
Go to the Data Resources tab, locate LUSID > Workspace and select Any.

Save your policy.
Assign the policy to a role.
Assign the role to the user you want to grant administrative workspace access to.
Read-only access to workspaces
To create a policy that grants read-only access to a workspace:
Navigate to Identity and Access > Policies and click the Create policy button.
.png?sv=2022-11-02&spr=https&st=2026-02-12T11%3A52%3A26Z&se=2026-02-12T12%3A03%3A26Z&sr=c&sp=r&sig=6l58HcWpAY9uzyGnAx6WUbE9mFRPvqzLV52kYA7x82I%3D)
Specify the following:
A unique Policy code
A friendly Description for the policy
Whether this policy should Allow or Deny access to the specified features and data
Go to the Data Resources tab and locate LUSID > Workspace.

Select the Read and ReadItem actions and specify the following for each workspace you want to control access to:
Selector:
IdentifierVisibility:
sharedName: The name of the workspace
Note
It’s important you select both the Read and ReadItem actions. The Read action controls access to see the workspace, while the ReadItem action controls access to see items within the workspace, including dashboards and dashboard sets.
Save your policy.
Assign the policy to a role.
Assign the role to the user you wish to grant read-only workspace access to.
Note
Workspace permissions govern access to everything within a workspace, including the dashboards and data they display (ReadItem activity).
You may only grant ReadItem access for an entire workspace; you cannot restrict access to particular items within a workspace.
If a dashboard set references a dashboard in another workspace, users must have read access to both workspaces.