---
title: Security permissions in Reporting
description: Learn how to control reporting access using Allowlists and Denylists. Grant or restrict user and team access to specific records while maintaining role-based permissions.
---

[Skip to content](https://gohub.casebook.net/knowledge/access-list-in-reporting#main-content)

[More support](https://gohub.casebook.net/knowledge/kb-tickets/new)

[![logo-raspberry (1)](https://gohub.casebook.net/hs-fs/hubfs/logo-raspberry%20(1).png?width=1286&height=255&name=logo-raspberry%20(1).png)](https://gohub.casebook.net/)

- [Knowledge Base](https://gohub.casebook.net/knowledge)
- [Video Library](https://gohub.casebook.net/video-library)
- [Still Need Help?](https://gohub.casebook.net/knowledge/kb-tickets/new)

Open main navigation

Close main navigation

- [Knowledge Base](https://gohub.casebook.net/knowledge)
- [Video Library](https://gohub.casebook.net/video-library)
- [Still Need Help?](https://gohub.casebook.net/knowledge/kb-tickets/new)
- [More support](https://gohub.casebook.net/knowledge/kb-tickets/new)

 Hi. How can we help?

- There are no suggestions because the search field is empty.

1. [Knowledge Base](https://gohub.casebook.net/knowledge)
2. [Reporting](https://gohub.casebook.net/knowledge/reporting)

# Security permissions in Reporting

### Overview

Reporting plays a central role in human services work. Supervisors use reports to understand team performance, program directors rely on them for funder and board updates, and frontline staff use reports to manage their caseloads.

**Access List in Reporting** allows your organization to control **who can see each report**, ensuring staff only view reports relevant to their role, program, or responsibilities. This reduces noise, supports privacy requirements, and gives leadership clearer visibility into scoped data.

With reporting access controls, you can:

- Grant report access to specific users or teams
- Prevent users from seeing organization-wide reports that do not apply to their work
- Reduce accidental exposure to sensitive or agency-wide insights
- Support supervisors who need reports scoped to their direct staff
- Ensure frontline workers only see data essential to their caseloads
- Allow **Reporting-Only access** scoped to specific reports (ideal for Board Members or Funders)

These controls create clearer role boundaries, stronger privacy protections, and a simpler reporting experience for staff.

![Screenshot 2026-01-09 at 2.11.55 PM](https://gohub.casebook.net/hs-fs/hubfs/Screenshot%202026-01-09%20at%202.11.55%20PM.png?width=670&height=344&name=Screenshot%202026-01-09%20at%202.11.55%20PM.png)

---

### How Reporting Access Works

Reporting access is managed through **Access Lists**, which determine who can view each report. There are two list types that control visibility:

#### Allow List

- Users or teams on the Allow List **can view the report**
- Applies only to users whose role includes **Limited Access: Reporting**
- Allows targeted access without granting full reporting visibility

#### Deny List

- Users or teams on the Deny List **cannot view the report**
- Applies even if the user:
  
    - Appears on the Allow List, or
    - Has broader reporting permissions in their role

 

**The Deny List always takes priority over the Allow List.**

This structure gives administrators precise control over report visibility across teams and programs.

---

### Setting Up Reporting Access

![Screenshot 2026-01-09 at 2.27.26 PM](https://gohub.casebook.net/hs-fs/hubfs/Screenshot%202026-01-09%20at%202.27.26%20PM.png?width=519&height=456&name=Screenshot%202026-01-09%20at%202.27.26%20PM.png)

#### 1. Open the Report Settings

1. Go to **Reporting**
2. Choose a Report
3. Navigate to the **Access** Column
4. Open the **Edit Access** modal

#### 2. Add Users or Teams to the Allow List

Use the Allow List to grant report visibility to:

- Individual users
- Teams
- Program units
- Supervisors
- Leadership roles

Users on the Allow List will see the report **unless they also appear on the Deny List**.

#### 3. Use the Deny List When Needed

Add users or teams to the Deny List when you need to:

- Block access for specific departments
- Restrict leadership-level or audit reports
- Remove access without changing role permissions
- Override inherited or accidental access

 

**Deny List access always overrides Allow List access.**

#### 4. Assign Limited Access: Reporting

To restrict a worker’s reporting experience to only assigned reports:

1. Go to **Admin**
2. Open **Roles & Permissions**
3. Select the worker’s role
4. Enable **Limited Access: Reporting**

Once enabled, users will **only see reports where they are included on the Allow List**.

**Important:** Limited Access: Reporting must be enabled for Access Lists to apply.

#### 5. Bulk Access Management

For larger organizations, administrators may be able to assign access to multiple reports at once. This is especially useful when:

- Onboarding new teams
- Restructuring programs
- Preparing for audits or funder reporting cycles

---

### What Workers Will See

- **If they are on the Allow List**
  
  The report appears in their reporting library
- **If they are on the Deny List**
  
  The report does not appear, even if they previously had access
- **If they have Limited Access: Reporting**
  
  They only see reports explicitly assigned through the Allow List
- **If no access was granted**
  
  The report does not appear in their reporting library

### Best Practices for Human Services Agencies

- Assign reports by **program**, not just individuals
- Give supervisors access to **all reports for their team**
- Limit frontline worker access to reports supporting their caseload
- Use Deny Lists for leadership, audit, or agency-wide dashboards
- Review access during onboarding, offboarding, and team changes
- Update access lists when responsibilities shift (e.g., caseload rotation)

---

### Frequently Asked Questions

- **Can a worker see a report if they’re not on the Allow List?**  
  Only if their role includes **full reporting access** and they are **not** listed on the Deny List.
- **What if someone is on both the Allow List and the Deny List?**  
  The **Deny List always overrides** the Allow List.
- **Does this control what data appears inside a report?**  
  No. Access Lists control **report visibility only**, not the underlying data or filters.
- **Do supervisors automatically see their team’s reports?**  
  No. Supervisors must be explicitly added to the **Allow List** for each report.

- [Getting Started With Casebook](https://gohub.casebook.net/knowledge/getting-started-with-casebook#main-content)

    - [Casebook Overview](https://gohub.casebook.net/knowledge/getting-started-with-casebook#casebook-overview)
    - [Getting Started for New Users](https://gohub.casebook.net/knowledge/getting-started-with-casebook#getting-started-for-new-users)
    - [Services in Casebook](https://gohub.casebook.net/knowledge/getting-started-with-casebook#services-in-casebook)
    - [Notes](https://gohub.casebook.net/knowledge/getting-started-with-casebook#notes)
- [Admin](https://gohub.casebook.net/knowledge/admin#main-content)

    - [Casebook Security](https://gohub.casebook.net/knowledge/admin#casebook-security)
    - [Roles and Permissions](https://gohub.casebook.net/knowledge/admin#roles-and-permissions)
    - [User Management](https://gohub.casebook.net/knowledge/admin#user-management)
    - [Notifications](https://gohub.casebook.net/knowledge/admin#notifications)
    - [Data](https://gohub.casebook.net/knowledge/admin#data)
    - [Field Configuration](https://gohub.casebook.net/knowledge/admin#field-configuration)
    - [Dynamic Fields](https://gohub.casebook.net/knowledge/admin#dynamic-fields)
    - [Forms](https://gohub.casebook.net/knowledge/admin#forms)
    - [Implementation & Adoption](https://gohub.casebook.net/knowledge/admin#implementation-adoption)
- [People](https://gohub.casebook.net/knowledge/people)
- [Intake](https://gohub.casebook.net/knowledge/intake)
- [Engage](https://gohub.casebook.net/knowledge/engage#main-content)

    - [Text Messages](https://gohub.casebook.net/knowledge/engage#text-messages)
    - [Configuration](https://gohub.casebook.net/knowledge/engage#configuration)
    - [Notes](https://gohub.casebook.net/knowledge/engage#notes)
- [Track](https://gohub.casebook.net/knowledge/track)
- [Access](https://gohub.casebook.net/knowledge/access)
- [Workflow & Tasks](https://gohub.casebook.net/knowledge/workflow-tasks)
- [Reporting](https://gohub.casebook.net/knowledge/reporting#main-content)

    - [Overview](https://gohub.casebook.net/knowledge/reporting#overview)
    - [Datasets](https://gohub.casebook.net/knowledge/reporting#datasets)
    - [Dashboards](https://gohub.casebook.net/knowledge/reporting#dashboards)
    - [Pre-built Reports](https://gohub.casebook.net/knowledge/reporting#pre-built-reports)
    - [Custom Reports](https://gohub.casebook.net/knowledge/reporting#custom-reports)
    - [Data Visualizations](https://gohub.casebook.net/knowledge/reporting#data-visualizations)
    - [Filters](https://gohub.casebook.net/knowledge/reporting#filters)
    - [Calculated Fields](https://gohub.casebook.net/knowledge/reporting#calculated-fields)
    - [Other](https://gohub.casebook.net/knowledge/reporting#other)
- [Audit Logs](https://gohub.casebook.net/knowledge/audit-logs)
- [Integrations](https://gohub.casebook.net/knowledge/integrations#main-content)

    - [Low-code incoming integrations with Zapier](https://gohub.casebook.net/knowledge/integrations#low-code-incoming-integrations-with-zapier)
    - [Custom incoming integrations with Casebook API](https://gohub.casebook.net/knowledge/integrations#custom-incoming-integrations-with-casebook-api)
    - [Custom outgoing integrations with Webhooks](https://gohub.casebook.net/knowledge/integrations#custom-outgoing-integrations-with-webhooks)
- [Program Area Specific](https://gohub.casebook.net/knowledge/program-area-specific#main-content)

    - [VOCA Reporting](https://gohub.casebook.net/knowledge/program-area-specific#voca-reporting)
- [Customer Support](https://gohub.casebook.net/knowledge/customer-support#main-content)

    - [Getting Unstuck](https://gohub.casebook.net/knowledge/customer-support#getting-unstuck)
    - [Account Management](https://gohub.casebook.net/knowledge/customer-support#account-management)
- [Product Release Notes](https://gohub.casebook.net/knowledge/product-release-notes#main-content)

    - [2026](https://gohub.casebook.net/knowledge/product-release-notes#2026)
    - [2025](https://gohub.casebook.net/knowledge/product-release-notes#2025)
    - [2024](https://gohub.casebook.net/knowledge/product-release-notes#2024)
    - [2023](https://gohub.casebook.net/knowledge/product-release-notes#2023)
    - [2022](https://gohub.casebook.net/knowledge/product-release-notes#2022)
    - [2021](https://gohub.casebook.net/knowledge/product-release-notes#2021)
    - [2020](https://gohub.casebook.net/knowledge/product-release-notes#2020)
- [Frequently Asked Questions](https://gohub.casebook.net/knowledge/frequently-asked-questions#main-content)

    - [Global](https://gohub.casebook.net/knowledge/frequently-asked-questions#global)
    - [Casebook Calendar](https://gohub.casebook.net/knowledge/frequently-asked-questions#casebook-calendar)
    - [Casebook Services](https://gohub.casebook.net/knowledge/frequently-asked-questions#casebook-services)
    - [Casebook Forms](https://gohub.casebook.net/knowledge/frequently-asked-questions#casebook-forms)
    - [Casebook Notes](https://gohub.casebook.net/knowledge/frequently-asked-questions#casebook-notes)
    - [cb Admin](https://gohub.casebook.net/knowledge/frequently-asked-questions#cb-admin)
    - [cb Track](https://gohub.casebook.net/knowledge/frequently-asked-questions#cb-track)
    - [cb Reporting](https://gohub.casebook.net/knowledge/frequently-asked-questions#cb-reporting)
    - [cb Access](https://gohub.casebook.net/knowledge/frequently-asked-questions#cb-access)
    - [Program Specific](https://gohub.casebook.net/knowledge/frequently-asked-questions#program-specific)

[![logo-raspberry-1-1](https://gohub.casebook.net/hs-fs/hubfs/logo-raspberry-1-1.png?width=32&height=30&name=logo-raspberry-1-1.png "logo-raspberry-1-1")](https://www.casebook.net/)

© 2025 Casebook. All rights reserved.

Casebook Knowledge Base [Video Library](https://gohub.casebook.net/video-library) [Still Need Help?](https://gohub.casebook.net/knowledge/kb-tickets/new)