Superset is shaped by three places at once: superset_config.py, its metadata database, and the admin UI. Nobody wants to learn all three just to change a logo or tighten a permission. The agent already knows them, and every change below is something you can ask for in one sentence and review as a diff. These ten customizations run from cosmetic to structural, roughly in the order you will want them.
1. Brand it as your company’s analytics
The default Superset name and logo make a fine demo and a forgettable product. The app name, logo, favicon, and default chart palette are all overrides in superset_config.py; the agent edits the file and restarts the service. Try: “Rename the app to Acme Analytics, add our logo, and make the default chart palette our brand colors.” Ten minutes later the tool your team opens every morning looks like it belongs to you.
2. Define certified metrics once
Nothing kills trust in a dashboard like three competing versions of revenue. Superset’s semantic layer lets you define metrics on a dataset: one named, documented formula that everyone charts with. Try: “On the orders dataset, define a certified metric called Net revenue as quantity times unit price minus refunds, with a short description, and make it the default in the chart builder.” Arguments about whose number is right end at the metric definition. Because the metric lives on the dataset, every new chart inherits it automatically, including the ones your team builds themselves.
3. Row-level security by region
Regional teams should see their region, not everyone’s. Superset’s row-level security filters a dataset with a SQL clause that can reference the current user; the agent writes the filter, maps users to regions, and tests with two accounts. Try: “Buyers should only see orders rows where the region matches their own region from the users table — set up row-level security and verify with a test login.” One dataset, many restricted views, and no copies to keep in sync. The verification step matters: have the agent log in as a test user from each region and confirm the row counts differ the way they should before you announce it.
4. A read-only viewer role
The default roles are blunt: Gamma users can build charts and query, Public is everyone. The agent composes a custom role with exactly what a viewer needs: open dashboards, no SQL Lab, no chart editor, no database connections. Try: “Create a ‘Viewer’ role that can open dashboards but cannot use SQL Lab, the chart editor, or database settings.” You stop wondering what a curious intern can touch.
5. Async queries for long SQL
SQL Lab queries that outlive the web request time out, and that teaches people to export to CSV and give up. Superset supports asynchronous execution through Celery and Redis: the query runs in a worker and the result lands in a results backend. Try: “Set up async SQL Lab queries with the Celery worker and Redis so a 10-minute query returns instead of timing out, and cache results for an hour.” Analysts stop splitting one question into five query chunks. It also smooths out peak load, because long queries queue in Celery instead of tying up web workers for everyone else.
6. Sensible dashboard defaults
Every dashboard should open in the state you actually want people to use: the last 30 days, the right time column, no surprise auto-refresh. The agent sets these per dashboard. Try: “Set the Sales overview dashboard to open on the last 30 days by default, use order_date as the time column, and disable auto-refresh.” First impressions of a dashboard form in the first three seconds, and an ‘all time’ default wastes them.
7. Custom CSS for wall displays
A dashboard on a TV wants different styling than a dashboard at a desk: no header, no edit affordances, larger numbers. Superset lets you attach CSS templates to a dashboard, and the agent can write one for your wallboards. Try: “Create a CSS template that hides the dashboard header and filter bar and enlarges the big-number charts for the NOC wall display.” The same dashboard serves desks and walls without forking it.
8. Lock down SQL Lab
SQL Lab runs as the database user Superset connects with, which is often far more powerful than analysts need. The agent creates a read-only database role, sets a statement timeout on it, and points Superset at it. Try: “Stop SQL Lab from running DELETE, UPDATE, or DDL: give Superset a read-only Postgres role with a 60-second statement_timeout.” People can still explore anything; they can no longer drop a table by accident. Superset itself has no switch for this, which surprises people — the honest fix is at the database layer, and the agent will tell you that plainly instead of pretending otherwise.
9. Embed a dashboard in your portal
Sometimes customers or staff should see one dashboard without holding a Superset account. Superset supports embedded dashboards with guest tokens, behind a feature flag plus an API call the agent can wrap in a small script. Try: “Enable embedded dashboards and write me a script that mints a guest token for the uptime dashboard so I can iframe it into our customer portal.” Your status page starts showing live numbers instead of a hand-updated screenshot. Keep the token minting script on the server only, and let the agent set an expiry on the tokens so a leaked iframe URL dies on its own.
10. Make upgrades boring
Superset releases often, and upgrading without a rehearsal is how dashboards die. The agent snapshots the metadata database and config, spins up a copy from last night’s backup, runs the upgrade there, and reports what broke before you touch production. Try: “Rehearse the next Superset upgrade on a copy of this instance, note anything that breaks, and write me a rollback plan.” You upgrade during business hours, calmly, with an exit door. Rehearsals like this are why some teams upgrade monthly while others stay a year behind out of fear.
See it in action
Official walkthroughs from the Apache Superset team:
Worth a watch next:
- Live Demo: Theming Apache Superset — the earlier theming deep-dive, the same branding-customization angle as the first item in this list.
- Live Talk: Semantic Layers in Apache Superset™ — the official talk on the semantic layer behind the certified-metrics customization in this article.
Start with the cosmetic ones; they build trust in the agent for the structural ones that follow. Every change here is a config edit or a permission, so ask the agent to show the diff before it applies anything. If you would rather skip the plumbing entirely, Apache Superset on OpenSysLab ships with the agent already wired into the server.