A workspace role such as Contributor governs broad capabilities like creating and editing items across an entire Fabric workspace. A museum volunteer who is not a member of that workspace at all still needs to open one specific report. Which mechanism grants her access to just that report without making her a workspace member?
Select an answer to reveal the explanation.
Short Explanation
Workspace roles are like an employee badge that opens every door in the building; item-level sharing is a single-use visitor pass that opens exactly one door and nothing else — no badge required.
Full Explanation
Item-level permissions in Fabric operate independently of workspace membership: an item owner (or someone with sufficient permission) can share a single report, lakehouse, or other artifact directly with an individual, granting access scoped to that one item without adding the recipient to the workspace's member list or exposing any other item in it. This matches the volunteer's situation exactly — she needs one report, nothing more. A higher workspace role like Member goes the opposite direction: it would make her a workspace member with broader capabilities across every item the role permits, far more access than 'one specific report' calls for, and it still requires membership, which the scenario explicitly avoids. Apache Airflow workspace settings configure orchestration environment options for the workspace and have no bearing on granting a person access to a report. Domain workspace settings govern how a workspace is organized under a Fabric domain for governance grouping purposes; they don't grant or restrict access to individual items either. An operational check: after sharing the report, confirm the volunteer's account does not appear in the workspace's member list, only in that report's individual access list.