What it does
Every saved report has a visibility level — private, program, institution, or organization — that controls who can see it. Widening visibility is a governed action. You state a reason, preview the audience, and the change is recorded in an audit trail. A dedicated access-audit area shows who is viewing shared reports, so authors and administrators can confirm sharing is appropriate.
Who it's for
Report authors (program administrators, directors, coordinators) who share reports and want to self-audit their reach, and institution administrators who oversee everything shared across the institution.
How it works
Setting visibility. When saving a report you choose its visibility: private (only you), program, institution, or organization. Anything wider than private opens a confirmation step that collects a reason. For an existing report, it also previews the estimated audience with a breakdown by role. The change and its reason are written to the audit trail.
Retracting. If a shared report should no longer be visible, the author can retract it to private from the report viewer. Retraction also collects a reason and is recorded in the audit trail.
Auditing access. Open Analytics & Reports in the left menu, then Access Audit. The page shows shared reports with their visibility, recent view counts, unique viewers, exports, and last activity over the past 30 days. Institution administrators see an institution-wide Institution audit tab. Program administrators see reports shared into their program, plus a Shared by me tab for their own reports (also on the Reports list). Each row opens a per-report access log. It lists individual events — views, exports, visibility changes — with who did them and when.
Sensitivity tags. Tags marking sensitive content are highlighted in the audit views and carried along with visibility changes, so reviewers can see at a glance which shared reports warrant closer attention.
Before you start
You need the program administration or institution portal.
You must be the report's author to change its visibility or retract it.
Have a reason ready. Sharing and retracting both ask for one before they proceed.
Do this
Open the report from Reports (
/analytics/reports), or open Save Report in Studio → you should see the Visibility field with Private, Program, Institution, and Organization options.Choose a wider level than the current one → a dialog opens titled "Share report at [scope]?", showing the estimated audience by role.
Enter a reason, then select Share at [scope] → the report is shared and the change is written to the audit trail.
To check viewers, open Report access audit (
/analytics/sharing) and select the Shared by me tab → you should see your reports with view counts and last-viewed dates.On that page, select a report to open its access log panel → you should see each view, export, and visibility-change event with who did it and when.
To stop sharing, open the report and select Retract to Private → confirm "Retract report to Private?" with a reason and Retract report → the report returns to Private.
You're done when
The report's visibility badge shows the new level and the change appears in its access log.
The Shared by me tab shows current view and export activity for anything you've shared.
A retracted report shows Private and drops out of its former audience's report lists.
Boundaries and limits
Visibility is scoped to your own platform tenancy — program, institution, or organization. There's no public link and no sharing outside the organization.
Visibility and status changes go through controlled, audited actions. They can't be edited silently as part of an ordinary save.
Only the report's author sees the Retract to Private action, and only while the report is shared wider than private.
Repeated views by the same person within the same hour are recorded once. Audit counts reflect distinct activity, not page refreshes.
Audit metrics on the access page cover the most recent 30 days. The per-report access log shows the most recent events, up to 100.
Who can see the audit data follows your access. Authors see their own reports, program administrators see their program's shared reports, institution administrators see the institution.
The audit trail is written server-side and can't be modified from the browser.
Common questions
Q: If I set a report to institution visibility, who exactly can see it? A: Everyone whose access falls under that institution. The audience preview shows the estimated total and a per-role breakdown before you confirm.
Q: Do I need approval from an administrator to share a report? A: No. Sharing takes effect immediately, but you must record a reason, and the action is visible to administrators in the access audit.
Q: Can I see who has viewed the report I shared? A: Yes. The "Shared by me" view shows view counts, unique viewers, and last-viewed dates, and the access log lists individual view events.
Q: What happens when I retract a report? A: Its visibility returns to private immediately, the retraction and your reason are recorded, and it drops out of the audience's report lists.
Related articles
