<!-- llms-explorer concept facts · https://llms-explorer.com/tree/access-control/ · pack 2026-10-02 · ~7114 tokens -->

# Access Control

> Depth-first rabbithole dossier for Access Control; source-anchored research pack.

Parent: [MongoDB Atlas Charts](https://llms-explorer.com/tree/mongodb-atlas-charts/) · 5 facets · 41 facts · page: https://llms-explorer.com/tree/access-control/

## Structure and components

- - AC-71 In on-prem Charts (2018–2019), Charts managed its own users. It had a `UserAdmin` role and the data source roles `Data Source Reader`, `Manager` and `Owner`. Dashboards were visible only to their creator until shared. https://www.slideshare.net/mongodb/bringing-data-to-life-with-mongodb-charts-148126509 [H] - AC-72 On-prem viewers also needed `Data Source Reader`, so the two-part check in AC-34 dates from that design. Same source. [H] - AC-73 MongoDB discontinued on-prem Charts in September 2021, after about a year of notice. https://www.mongodb.com/community/forums/t/how-to-use-mongod — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/rabbithole-synthesis.md#g-history`
- - Charts network access and egress IPs - Charts REST API and API key roles - Scheduled dashboard reports, which deliver data outside the dashboard permission check - Charts Views as a pre-filter layer - The Data Federation data source path - Atlas private endpoints with Charts - On-prem Charts 19.x history — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/rabbithole-synthesis.md#handoffs-siblings-surfaced-not-chased`
- - Charts data source network access and egress IPs (parent topic) - Charts REST API and programmatic API key roles - Scheduled dashboard reports, which deliver data outside the dashboard permission check - Charts Views as a pre-filter layer (C54) — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/reports/mechanism.md#handoffs-siblings-surfaced-not-chased`

## How it works

- 37. The parent says "data source access is project-scoped". That is true by default only. Since v1.34/v1.35 (2022), organization-wide sharing can expose a data source to organization members outside the project (claims 13, 32). 38. The parent says Org Owners can access Charts in any project. The Atlas role definitions confirm this, because `ORG_OWNER` inherits `Project Owner` in every project (claim 15). — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/reports/history.md#d-deltas-and-corrections-to-inherited-parent-facts`

## Problems, failure modes and limitations

- - **"Org Owner can access Charts in any project."** M, H and E confirm this from the role reference (AC-12). P marked it unverified because it relied on the launch page. The role reference states it directly, so it holds. New detail: this inherited access is not shown on the project access list (AC-13). - **"Data source access is project-scoped."** This is true by default only. Since v1.34/v1.35 (2022), organization-wide sharing can expose a data source outside the project (AC-24 to AC-26). - **"Charts egress IPs must be on the cluster IP allowlist."** E and P found no Charts or Atlas page tha — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/rabbithole-synthesis.md#i-child-only-corrections-to-inherited-parent-facts`
- 32. By default, an embedded chart allows no filter fields. Pre-filters and filters fail until an author allows at least one field. Filtering on a field that is not allowed returns an error. https://www.mongodb.com/docs/charts/filter-embedded-charts/ 33. Each sub-field of an embedded document must be allowed explicitly. For example, allow `favorites.color`, not `favorites`. https://www.mongodb.com/docs/charts/filter-embedded-charts/ 34. Allowed filter fields constrain which fields a filter may use, not which values. If `tenantId` is an allowed field, a client can change the tenant value in a cl — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/reports/practice.md#f-filters-as-the-row-level-control`
- - AC-01 You can access Charts with any Atlas organization role, or with any project role that can read data. https://www.mongodb.com/docs/charts/launch-charts/ [M] - AC-02 The launch page says every project role except `Project Read Only` can launch Charts. https://www.mongodb.com/docs/charts/launch-charts/ [M,P] - AC-03 Each Charts instance belongs to one Atlas project. It can visualize only clusters in that project. https://www.mongodb.com/docs/charts/launch-charts/ [P] (M found no page that states this directly.) - AC-04 The first launch of Charts in a project creates the service user `char — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/rabbithole-synthesis.md#a-atlas-role-gate`
- - AC-15 Project Owner and the "Data" roles can view and create charts by default. A Project Owner can turn "Can view charts with data in this data source" on or off for Non-Data roles, one data source at a time. https://www.mongodb.com/docs/charts/manage-data-sources/ [M,H,P] - AC-16 Charts maps Atlas roles to Charts project roles automatically. Hovering over a role in the UI shows the mapping. https://www.mongodb.com/docs/charts/data-source-permissions/ [M] - AC-17 The mapping is: Project Owner → Owner; the three Data Access roles → Author; Project Read Only and Project Cluster Manager → none — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/rabbithole-synthesis.md#b-data-source-permissions`
- - AC-27 Dashboards have three nested permission levels: Viewer, Author, Owner. https://www.mongodb.com/docs/charts/dashboards/dashboard-access/dashboard-permissions/ [M,H,E,P] - AC-28 A Viewer can view, filter, and refresh a dashboard, but cannot change it. https://www.mongodb.com/docs/charts/dashboard-permissions/ [M,E,P] - AC-29 A Viewer's auto-refresh setting is stored only in their browser. It is not saved with the dashboard or shared. https://www.mongodb.com/docs/charts/dashboards/dashboard-access/dashboard-permissions/ [E] - AC-30 An Author chooses which fields unauthenticated embeds may — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/rabbithole-synthesis.md#c-dashboard-permissions-and-ownership`
- - AC-42 A public link gives Viewer rights to anyone who has it, whatever their user permissions. Every data source on the dashboard needs Unauthenticated External Data Access. https://www.mongodb.com/docs/charts/dashboard-permissions/ [M,H,E,P] - AC-43 Charts cannot verify who holds a link. MongoDB says not to share links to dashboards with sensitive data. https://www.mongodb.com/docs/charts/dashboards/dashboard-access/dashboard-permissions/ [E,P] - AC-44 A public link can have a passcode, added in v1.44.0 (2024-04-30). After a viewer enters it, access lasts 5 days. The Owner can regenerate th — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/rabbithole-synthesis.md#d-public-links-and-ip-policy`
- 1. There are three dashboard roles: Viewer, Author and Owner. A Viewer cannot change a dashboard at all. https://www.mongodb.com/docs/charts/dashboards/dashboard-access/dashboard-permissions/ 2. Only someone with the Owner role on a dashboard can change that dashboard's permissions. https://www.mongodb.com/docs/charts/dashboards/dashboard-access/dashboard-permissions/ 3. New dashboards are private by default. Only the Owner can see one until they share it. https://www.mongodb.com/docs/charts/dashboards/dashboard-access/dashboard-permissions/ 4. To see a chart, a user needs two things: a projec — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/reports/edge-cases.md#dashboard-permissions`
- 11. Charts cannot tell who holds a shared dashboard link. MongoDB says not to share links to dashboards that show sensitive data. https://www.mongodb.com/docs/charts/dashboards/dashboard-access/dashboard-permissions/ 12. After a viewer enters a passcode, the dashboard stays visible for five days without asking again. Changing or revoking access therefore does not cut off a session that is already open. https://www.mongodb.com/docs/charts/dashboards/dashboard-access/dashboard-permissions/ 13. A public link shows nothing for a data source until a Project Owner turns on Unauthenticated External D — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/reports/edge-cases.md#link-sharing-and-passcodes`
- 14. Only a Project Owner can connect or disconnect data sources and deployments, change data source settings, or change data source role permissions. https://www.mongodb.com/docs/charts/manage-data-sources/ 15. Charts connects to every deployment and data source in the project by default. Exposure is opt-out, not opt-in. https://www.mongodb.com/docs/charts/manage-deployment/ 16. A user sees a cluster in Charts only if they hold Project Data Access Read Only or higher. https://www.mongodb.com/docs/charts/manage-deployment/ 17. Users with Project Read Only can open Charts only if a Project Owner — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/reports/edge-cases.md#how-atlas-roles-reach-charts`
- 23. External sharing is off by default for every data source. When enabling it, you choose either Authenticated or Unauthenticated External Data Access. https://www.mongodb.com/docs/charts/manage-data-sources/ 24. MongoDB recommends Unauthenticated External Data Access only for non-sensitive data. https://www.mongodb.com/docs/charts/manage-data-sources/ 25. If you turn off external sharing, every chart on that data source stops rendering at once. Revocation is immediate and hits every embed together; you cannot revoke one embed at a time. https://www.mongodb.com/docs/charts/manage-data-sources — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/reports/edge-cases.md#external-sharing-and-revocation`
- - **Using the client `filter` for tenant scoping.** A 2026-03-31 third-party guide scopes tenants with the client SDK `filter` option ("Only show data belonging to the current user's organization"). https://oneuptime.com/blog/post/2026-03-31-mongodb-how-to-embed-atlas-charts-in-your-web-application/view The official docs say page code can change `filter` through `setFilter`, and they put per-user scoping in server-side injected filters. https://www.mongodb.com/docs/charts/embedded-charts-options/embedded-sdk/ https://www.mongodb.com/docs/charts/filter-embedded-charts/ Both sides are kept. The — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/reports/edge-cases.md#unresolved-disagreements-and-doc-gaps`
- 1. Dashboards have three permission levels: `Viewer`, `Author`, and `Owner`. Each level includes the privileges of the level below it. https://www.mongodb.com/docs/charts/dashboards/dashboard-access/dashboard-permissions/ 2. `Author` adds these actions: change charts, filters, and layout, rename the dashboard, and choose which fields unauthenticated embedded charts can filter on. `Owner` adds managing permissions and deleting the dashboard. https://www.mongodb.com/docs/charts/dashboards/dashboard-access/dashboard-permissions/ 3. The creator of a dashboard is always `Owner`. You cannot remove t — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/reports/history.md#a-current-model-as-of-2026-10-02`
- - C1. You can access Charts with any Atlas Organization Role, or with any Project Role that can read data from Atlas. https://www.mongodb.com/docs/charts/launch-charts/ - C2. The launch prerequisite is any Project Role except `Project Read Only`. https://www.mongodb.com/docs/charts/launch-charts/ - C3. The first launch of Charts in a project creates a user named "Charts User" with the `Project Charts Admin` role. Charts uses this user to access cluster data. https://www.mongodb.com/docs/charts/launch-charts/ - C4. The Charts User's name has the form `charts+<PROJECT-ID>@mongodb.com`. https://w — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/reports/mechanism.md#a-layer-1-atlas-role-gate`
- - C10. Only Project Owner can connect, disconnect, or change the settings of a Charts data source. https://www.mongodb.com/docs/charts/data-source-permissions/ - C11. Charts automatically lets Project Owner and the "Data roles" view and create charts on a data source. https://www.mongodb.com/docs/charts/manage-data-sources/ - C12. For Non-Data roles, a Project Owner can turn "Can view charts with data in this data source" on or off for each data source. https://www.mongodb.com/docs/charts/manage-data-sources/ - C13. Charts maps each Atlas user role to a Charts project role automatically. Hover — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/reports/mechanism.md#b-layer-2-data-source-permissions`
- - C20. Dashboards have three permission levels, each including the one below: Viewer, Author, Owner. https://www.mongodb.com/docs/charts/dashboards/dashboard-access/dashboard-permissions/ - C21. A Viewer can open the dashboard, filter it, and refresh it, but cannot change it. https://www.mongodb.com/docs/charts/dashboard-permissions/ - C22. An Author can also add, change, and delete charts and filters, change the layout, rename the dashboard, and choose which fields unauthenticated embedded charts may filter on. https://www.mongodb.com/docs/charts/dashboard-permissions/ - C23. An Owner can als — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/reports/mechanism.md#c-layer-3-dashboard-permissions`
- In scope: how Atlas Charts decides who can see or change dashboards, charts, and data. That covers Atlas project and org roles as they apply to Charts, data source permissions, dashboard permissions and ownership, org-wide and public-link sharing, external sharing for embedding, embedding authentication providers, and filter controls (allowed filter fields, injected filters). It also covers the operational trade-offs and failure modes of each. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/reports/practice.md#scope`
- 1. Each Atlas Charts instance belongs to exactly one Atlas project. It can only visualize data from clusters in that same project. https://www.mongodb.com/docs/charts/launch-charts/ 2. All project users can reach that project's Charts instance unless their only role is `Project Read Only`. https://www.mongodb.com/docs/charts/launch-charts/ 3. The Atlas roles reference qualifies claim 2. A `Project Read Only` user gets Charts access only if a `Project Owner` invites them to the project. Even then they cannot see data until the Project Owner grants data source access. https://www.mongodb.com/doc — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/reports/practice.md#a-role-model-who-reaches-charts-at-all`
- 7. Charts maps Atlas roles to data source permissions automatically, as follows. https://www.mongodb.com/docs/charts/data-source-permissions/ - `Project Owner` gets Owner. - `Project Data Access Admin`, `Project Data Access Read/Write`, and `Project Data Access Read Only` get Author. - `Project Read Only` and `Project Cluster Manager` get nothing until they are granted Viewer. 8. A Project Owner can let Non-Data roles view charts for a specific data source with the "Can view charts with data in this data source" toggle. https://www.mongodb.com/docs/charts/manage-data-sources/ 9. Charts v1.33.1 — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/reports/practice.md#b-data-source-permissions`
- 12. A dashboard has three permission levels. https://www.mongodb.com/docs/charts/dashboard-permissions/ - Viewer can view, filter, and refresh, but cannot modify. - Author has Viewer rights plus the ability to change charts, filters, layout, and name. An Author also chooses which fields unauthenticated embeds may filter on. - Owner has Author rights plus the ability to manage permissions and delete the dashboard. 13. Claim 12 means that choosing which fields unauthenticated embeds may filter on is an Author-level right, not Owner-only. Anyone with Author on a dashboard can therefore widen the — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/reports/practice.md#c-dashboard-permissions-and-ownership`
- 19. Sharing a dashboard with the whole organization grants Viewer only. It needs a second switch on each data source: "All users in the organization can view data in this data source". https://www.mongodb.com/docs/charts/dashboard-permissions/ · https://www.mongodb.com/docs/charts/data-source-permissions/ 20. If the organization uses an SSO provider, org-shared dashboards prompt users to sign in through that provider. Users who authenticate through the provider do not need an Atlas account. https://www.mongodb.com/docs/charts/dashboard-permissions/ 21. A public link lets anyone with the link v — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/reports/practice.md#d-org-wide-and-public-sharing`

## Comparisons and alternatives

- - **Read Only access.** The launch docs say `Project Read Only` users have no access to Charts (claim 2). The roles reference says they get access if invited, but see no data until granted data source access (claim 3). Both sources are kept here, not merged into one rule. - **Auth provider list.** Release notes for v1.13.0 (2020-04-30) say Charts supports "Custom JWT, Atlas App Services, and Google" providers. The current configuration page lists only Google and Custom JWT (claim 27). This suggests App Services auth was dropped, but no dated removal note was found. https://www.mongodb.com/docs — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/reports/practice.md#unresolved-disagreements-and-corrections-to-inherited-parent-facts`
- - https://www.mongodb.com/docs/charts/dashboard-permissions/ - https://www.mongodb.com/docs/charts/data-source-permissions/ - https://www.mongodb.com/docs/charts/manage-data-sources/ - https://www.mongodb.com/docs/charts/dashboards/dashboard-access/dashboard-ownership/ - https://www.mongodb.com/docs/charts/launch-charts/ - https://www.mongodb.com/docs/charts/configure-auth-providers/ - https://www.mongodb.com/docs/charts/embed-chart-jwt-auth/ - https://www.mongodb.com/docs/charts/filter-embedded-charts/ - https://www.mongodb.com/docs/charts/release-notes/ - https://www.mongodb.com/docs/atlas/r — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/reports/practice.md#sources`
- https://www.mongodb.com/docs/charts/configure-auth-providers/ [M,H,E,P] - AC-50 An RS256 key can be a JWK, a JWKS URL (Charts tries each key in turn), or a PEM public key. HS256 uses a shared secret. JWK and JWKS support arrived in v1.27.0 (2021-09-13). https://www.mongodb.com/docs/charts/configure-auth-providers/ https://www.mongodb.com/docs/charts/release-notes/ [M,H,E,P] - AC-51 Charts accepts a Google token if it is a well-formed JWT from the correct issuer that matches the configured Client ID. https://www.mongodb.com/docs/charts/configure-auth-providers/ [M] - AC-52 Charts does not refre — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/rabbithole-synthesis.md#e-embedding-authentication`
- | # | Topic | Side A | Side B | Status | |---|---|---|---|---| | D1 | Project Read Only | Launch page: every project role *except* Project Read Only can launch Charts (AC-02) | Role reference: allowed if invited, but no data without a data source grant (AC-08). v1.17.0 added sample-data authoring (AC-75) | Unresolved. The sources may describe one model at different dates | | D2 | Data source tiers | P: the current page maps roles to Owner, Author, or none (AC-17) | H: that mapping came only from a search summary of the old `saas/` page. The current docs use a Data vs Non-Data toggle (AC-15). T — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/rabbithole-synthesis.md#disagreements-kept-side-by-side`
- 28. There are two embedding auth providers: Google and Custom JWT. Only a Project Owner can configure them. https://www.mongodb.com/docs/charts/configure-auth-providers/ 29. Custom JWT accepts HS256 or RS256. RS256 keys come from a JWK, a JWKS URL (Charts tries each key in turn) or a PEM public key. https://www.mongodb.com/docs/charts/configure-auth-providers/ 30. Charts requires both `exp` and `iat`, and rejects tokens whose lifetime (`exp` minus `iat`) is over 24 hours. `aud` is optional. https://www.mongodb.com/docs/charts/configure-auth-providers/ 31. Delta from the standard: RFC 7519 make — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/reports/edge-cases.md#embedding-authentication`
- 22. v1.0.0 (2018-12-11) is the earliest Atlas Charts release listed. 23. v1.4.0 (2019-06-12, GA) added a "New Data Source permissions model". Its `Viewer` role grants access to data for viewing but not authoring. 24. v1.5.0 (2019-08-07) allowed custom filters on embedded charts that use Verified Signature authentication. 25. v1.8.0 (2019-11-11) added public-link dashboard sharing and redesigned the Data Source Permissions and Dashboard Permissions dialogs. A summary-model paraphrase wrongly credited the Viewer role to v1.8; the verbatim notes say v1.4. 26. v1.10.0 (2020-02-05) released the Emb — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/reports/history.md#c-atlas-charts-evolution-official-release-notes`
- - **Release-note chronology:** the official page dates v1.47.0 to 2024-10-27 but v1.49.0 to 2024-05-21, so a higher version has an earlier date. One of the two dates is probably a doc error. Not resolved. https://www.mongodb.com/docs/charts/release-notes/ - **Data source Viewer/Author/Owner tiers:** a search-engine summary of the old `saas/data-source-permissions` page gave this default mapping: Project Read Only and Cluster Manager get none, the Data Access roles get Author, Project Owner gets Owner. The current docs use a Data vs Non-Data toggle instead (claim 11). I could not fetch the arch — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/reports/history.md#unresolved-disagreements-and-gaps`
- - C33. You can embed with an iframe (static HTML) or with the Embedding SDK (programmatic). https://www.mongodb.com/docs/charts/embedding-charts/ - C34. An embed is either unauthenticated (anyone can view) or authenticated through an Embedding Authentication Provider. https://www.mongodb.com/docs/charts/embedding-charts/ - C35. The authenticated request flow works like this. The SDK sends the chart ID and the user's token to Charts. Charts validates the token with the provider. If the token is valid for that chart ID, Charts runs the pipeline against Atlas with any injected filters and returns — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/reports/mechanism.md#d-layer-4-embedding-authentication`
- 1. **Project Read Only access.** The Charts launch page lists every project role *except* Project Read Only as able to launch Charts (C2). The Atlas role reference says Project Read Only can use Charts if invited, and can see data only with explicit data source access (C7). The v1.17.0 release notes let that role build charts from sample data (C8). These may be one model described at different points in time, but the sources do not reconcile it. 2. **Supported authentication providers.** The v1.13.0 release notes (2020) list Custom JWT, Atlas App Services, and Google. The current configure-pro — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/reports/mechanism.md#unresolved-disagreements`

## Facts and statements

- Two other sources added nothing. The GitHub SDK README (github.com/mongodb-js/charts-embed-sdk) gave no access-control detail beyond links. The Medium JWT tutorial returned HTTP 403. No standards body or independent security audit of Charts was found. All authoritative claims rest on MongoDB's own docs. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/reports/practice.md#quality-gate`
- - **In scope:** the Atlas role gate, data source permissions, dashboard permissions and ownership, project, organization and public sharing, embedding authentication as an access gate, filter-based row scoping, and how these changed over time. - **Out of scope:** Atlas network security in general, the Charts REST API and API keys, cost, refresh and caching, drilldown, and the SDK surface beyond authentication. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/rabbithole-synthesis.md#scope`
- Two settings widen access more than you might expect: - **A public link** skips user permissions. Only the data source's external-access flag protects it. - **An invalid embed token** falls back to the unauthenticated view if unauthenticated access is also enabled. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/rabbithole-synthesis.md#mechanism-summary`
- In scope: how Charts decides who can see or change a chart, dashboard, or data source. That covers dashboard roles, data source permissions, how Atlas user roles map to Charts, organization and public sharing, embedding authentication as an access gate, and how all of these changed over time. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/reports/history.md#scope`
- Out of scope: network access (IP allowlists, egress IPs), the Charts REST API and API keys, the cost model, and the embedding SDK beyond its authentication role. Those are sibling frontier items. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/reports/history.md#scope`
- - Embedding authentication providers and the deprecation of Verified Signature mode - Charts network access and IP allowlisting - Charts on-premises (19.x) product history — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/reports/history.md#handoffs-siblings-surfaced-not-chased`
- **Out of scope:** Atlas network access and IP allowlists, the Charts REST API and API keys, cost, refresh and caching, and drill-down. These are sibling or parent topics. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/reports/mechanism.md#scope`
- Two settings widen access more than you might expect. First, a public link bypasses user permissions completely, so it relies only on the data source's external-access flag. Second, an invalid token falls back to the unauthenticated view whenever unauthenticated access is also enabled. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/access-control-c3ceee351e/reports/mechanism.md#mechanism-summary`

## Related concepts

- Access — is a part of Access Control
- Control — is a part of Access Control
