Files
govoplan-reporting/docs/ADMIN_GUIDE.md
T

43 lines
1.9 KiB
Markdown

# Reporting Administration Guide
## Definition graph
Reporting definitions form an exact graph:
```text
Dataset revision -> Semantic-model revision -> Report revision
-> Quality-plan revision
```
Create parents before children. An active child may reference only an active,
existing parent revision. Editing creates a new immutable revision and
requires the currently observed revision number. Existing runs continue to
reference the historical revisions they used.
Datasets may bind a static fixture, a pinned Dataflow output, or a capability
published by a source-owning module. Do not expose another module's ORM or an
unbounded SQL connection as a report source. Configure an explicit schema,
freshness policy, source fingerprint expectations, purpose, privacy,
retention, and a row-policy provider where source access alone is not enough.
## Access and publication
Tenant-visible definitions are readable by principals with Reporting read
permission. Restricted reports use normalized account, identity, group, role,
function, assignment, organization-unit, or service-account grants. The
creator and Reporting administrators retain management access.
Scheduled output publication requires an installed capability implementing
the Reporting publication-target contract. The target receives one immutable
execution payload and an idempotency key. It must return bounded evidence and
must not expose credentials in that evidence.
## Import assessments
Import assessment accepts declarative metadata only. Native datasets,
dimensions, hierarchies, measures, parameters, tables, pivots, charts,
quality assertions, and saved views map exactly. Provider-specific formatting,
dialect functions, and dashboard layouts require explicit approximation
acceptance. Raw SQL, procedures, scripts, implicit authorization, unchecked
functions, and unknown features block activation.