Best practice to enable sharing the Ramon presented or between Shared (all) and Restricted?

(Lingering question from the chat)

Are the Monitoring tools meant to be self-serve using available data in QuickSight from those various platforms (CloudTrail, CloudWatch, etc.) or do we need AWS support to get those dashboards and reports set up? I’m thinkin of this example that was given to me recently.

The shared pattern example with Finance and Restricted folders is a valuable one for us. Initially, we planned to use Restricted strictly for Finance builds, collaboration and sharing within their own space. If they had more publicly consumed data assets, we were going to use regular Shared folders with an approval process step in place since the data would likely contain sensitive data. What I understand is that we don’t need to create another space for public vs. restricted. If that is true are there any gaps in admins or contributors accidentally sharing Finance restricted data assets in the subfolder intended for Everyone? Restricted folder features/functionality seem to prevent this as you cannot share any restricted data assets outside of a restricted folder so the guardrails are built in. Long story to ask if it is best practice to enable sharing the Ramon presented or between Shared (all) and Restricted?

1 Like

Hello!

For monitoring QuickSight with CloudWatch, you shouldn’t need AWS support to set that up. I recommend following the guides laid out below:

Here is a brief explainer on how to get the log data into QuickSight to make custom dashboards:

For the second question about managing folder permissions, you should always create architecture with that adheres to the principle of least privilege. For this use case, I would create permissions for users and groups on the folders so that only those who should be able to access them have them available: