# Build a Private Dashboard from Your Data in Lovable

> Turn form submissions in Lovable Cloud into a private admin dashboard with counts, a chart and a status table, behind an email and password sign-in.

Source: https://learn.ynteractive.com/content/lovable-dashboard-with-login · Updated 2026-10-10 · Free from Stepthrough (https://learn.ynteractive.com)

## Practice it step by step

[Start the free practice](https://learn.ynteractive.com/modules/lovable-dashboard)

You do every step yourself in a practice copy of Lovable. It checks your work as you go, and “Do it for me” finishes any step you get stuck on. Free, about 9 minutes, and nothing touches your real accounts. [Open full screen](https://learn.ynteractive.com/modules/lovable-dashboard)

Free · Live now · [Build Apps with Lovable](https://learn.ynteractive.com/content/course/build-apps-with-lovable) · [Lovable](https://learn.ynteractive.com/content/tool/lovable) · Lovable Cloud · ~9 min · 34 steps · Beginner

Updated October 10, 2026. Built against the tool’s current screens and checked step by step. [How we check this lesson](https://learn.ynteractive.com/content/about#how-we-check)

A form that saves to a database is useful, but reading raw rows is not how you want to start your day. In this free, interactive [Lovable](https://learn.ynteractive.com/content/tool/lovable) tutorial you turn a small salon's booking requests into a private dashboard: how many came in this week, which services people want, and a table of every request with its status. You add a sign-in only the owner can use, switch off sign-up, test it in the preview, add a "Mark as contacted" button by chatting, check the database rules and publish.

## At a glance

| Question | Answer |
| --- | --- |
| What you build | Turn the booking requests in your Lovable Cloud database into a private dashboard with counts, a chart and a status table. Add a sign-in only you can use, test it in the preview, improve it by chatting, check the access rules and publish. |
| Tools | Lovable |
| Time | About 9 minutes, 34 steps in 6 parts |
| Level | Beginner, no coding needed |
| Cost | Free |
| Ways to learn it | [Practice it step by step](https://learn.ynteractive.com/modules/lovable-dashboard) |

### The 6 parts, in short

1. Ask for the dashboard: Click the chat box, Describe the dashboard, Send it, Allow the database change.
2. Add your owner account: Open More, Open Cloud, Open Users, Add a user, and 4 more steps.
3. Turn off sign-up: Open Auth settings, Turn on Disable sign-up, Save, Close More.
4. Sign in and look: Open the page selector, Go to Admin, Enter your email, Enter your password, and 1 more step.
5. Improve it by chatting: Click the chat box, Ask for one change, Send it, Mark a request as contacted, and 1 more step.
6. Check the rules and publish: Open More, Open Cloud, Open booking_requests, Open RLS policies, and 4 more steps.

**Start here first:** [Build a Landing Page with Lovable from One Prompt](https://learn.ynteractive.com/content/lovable-landing-page-from-one-prompt) (module 1 of Build Apps with Lovable)

**In the course:** [Part 10 · Build Apps with Lovable](https://learn.ynteractive.com/content/course/part-10-build-apps-with-lovable) (Module 50 of the [full course](https://learn.ynteractive.com/content/course))

## What you will build

You continue the Hazelbrook Hair Studio site from the first three modules of this course. Hazelbrook is a made-up salon on Orchard Lane. Its site has a booking request form that saves every request to a table called booking_requests in Lovable Cloud, the [backend](https://learn.ynteractive.com/content/glossary/frontend-vs-backend) built into Lovable.

By the end of this module the site has a private page at /admin. It shows three cards (requests this week, requests still new, and the most requested service), a bar chart of this week's requests by service, and a table of every request with the name, service, phone and email, date and a status of New or Contacted. Signed-out visitors who open /admin are sent to a sign-in page, and the public site has no link to either page.

## The steps, in order

The module has 34 steps across six short chapters. Each one mirrors a real screen in Lovable.

- Ask for the dashboard: click Ask Lovable in the project chat and describe the page. Say where it goes (/admin, with a sign-in page at /admin/login), who may open it (signed-in users only, email and password, no sign-up form), what changes in the database (a status column, and rules that let signed-in users read requests and change their status while visitors can still only send one), and what the page shows. Send it. If your Modify database permission is set to Ask each time, Lovable shows the SQL first and you click Allow; by default it goes ahead without asking.
- Add your owner account: open More in the project toolbar, then Cloud, then Users. There are no users yet. Click Add user, choose Create new user, enter your email and a strong password, and click Create user. Accounts created this way are confirmed automatically.
- Turn off sign-up: click Auth settings. Email is the only sign-in method switched on. Turn on Disable sign-up, so nobody can create an account from outside, even though the sign-in page has no sign-up form. Save, and close More.
- Sign in and look: click the page selector above the preview, pick Admin, and see that you are sent to the sign-in page. Sign in with your account and the dashboard appears with the real requests, because the preview and the published site share the same database.
- Improve it by chatting: ask Lovable for a "Mark as contacted" button on every new request and a status filter with All, New and Contacted. Mark one request as contacted, watch the count go down, and filter to New to see who you still need to call.
- Check the rules and publish: open More, Cloud, the booking_requests table and its RLS policies. There are three rules: anyone can add a request, and only signed-in users can read requests or update them. Close More, click Publish, then Publish changes, and open your live site.

## How the sign-in keeps the requests private

Hiding a page is not the same as protecting data. What protects the booking requests is row level security (RLS) in the database: rules that say who can read, add or change each row. In this module the table keeps its rule that lets anyone add a request, and gets two new rules that let only signed-in users read requests and change their status. Because the database checks these rules on every request, someone who finds the /admin address still sees nothing without signing in.

Sign-in only matters if strangers can't make accounts. That is why you switch on Disable sign-up under Users, then Auth settings. With sign-up off, existing users can still sign in, and you can still add staff yourself with Add user. Keep in mind that every signed-in user can read the requests with these rules. If you later let customers create accounts, ask Lovable first to limit the dashboard to an admin role.

Lovable also runs a quick security scan each time you publish, which checks your database access rules, and you can run a deeper scan whenever you like.

## Tips for a dashboard you will actually use

Ask for the few numbers you check every day, not everything at once. Start with a small first version, test it in the preview, then add one change at a time by chatting, like a filter or a button. Name your table and columns in the request when you already have them, so Lovable builds on your real data instead of inventing new tables.

Test the protection as well as the page: open /admin while signed out, and make sure it sends you to the sign-in page. Use a strong password that only you know.

## How the interactive lesson works

Each step plays first in the Watch panel with a short voice-over, then you do it yourself in Your turn, on a practice copy of Lovable. Every click is checked, and Do it for me helps if you get stuck. No database is changed, no account is created, nothing is published and no credits are used. The requests, names and password in the lesson are made up.

## Try it yourself, free

Reading the steps is a start. Doing them is how it sticks. The interactive module walks you through every click in a practice copy of Lovable, checks each step, and never touches your real accounts.

[Start “Build a Private Dashboard from Your Data in Lovable”](https://learn.ynteractive.com/modules/lovable-dashboard)

## Step by step: Build a Private Dashboard from Your Data in Lovable

All 34 steps of the interactive module, in order. In the module you watch each one, then do it yourself in a practice copy that checks your work.

### 1. Ask for the dashboard

1. **Click the chat box.** Booking requests from the Hazelbrook site land in the **booking_requests** table from module 2. Click **Ask Lovable...**
   Since module 2, booking requests from the Hazelbrook site have been landing in your Cloud database. Reading them in a table works, but a simple dashboard is nicer. Let's build a private page that only you can open.
2. **Describe the dashboard.** Say where it goes, who may see it, what may change in the database, and what it shows. Paste in the request.
   A good request says where the page goes, who may open it, what changes in the database, and what the page shows. Here: a page at slash admin with its own sign-in page and no sign-up form, a new status column, three cards, a chart by service, and a table.
   ```text
   Add a private admin dashboard at /admin for the salon owner, with a sign-in page at /admin/login (email and password only, no sign-up form, and no link to either page on the public site). Only signed-in users can open /admin; anyone else is sent to the sign-in page. Add a status column to booking_requests (New or Contacted, default New). Signed-in users can read requests and change their status; visitors can still only send a request. On the dashboard show three cards (requests this week, requests still New, most requested service this week), a bar chart of this week's requests by service, and a table of every request, newest first, with name, service, phone and email, date and status. Use the site's colors and fonts.
   ```
3. **Send it.** Click the **send arrow**.
4. **Allow the database change.** Here **Modify database** is set to **Ask each time**, so Lovable shows the SQL it wants to run first. (The default is Always allow, and then it goes ahead without asking.) Click **Allow**.
   By default, Lovable changes your database without asking. Here, the Modify database permission is set to Ask each time, so you see the change first: the status column and the new access rules.

### 2. Add your owner account

5. **Open More.** Lovable built the pages. There are no accounts yet, so nobody can sign in. Click **More** in the toolbar (the stacked icon after **Code**).
   Lovable built the sign-in page and the dashboard. But there are no accounts yet, so nobody can sign in, not even you. You'll create yours in Cloud.
6. **Open Cloud.** Click **Cloud** in the list on the left.
7. **Open Users.** Click **Users**.
   This is where you see everyone who has an account in your app.
8. **Add a user.** No users yet. Click **Add user**.
   No users yet.
9. **Create new user.** Pick **Create new user**. Accounts you create here are confirmed automatically, so no email check is needed.
   Accounts you make here are confirmed automatically, so you don't have to click a link in an email.
10. **Enter your email.** Type the owner's email: **jess@example.com**
    Here, it's Jess, the owner: jess at example dot com.
11. **Choose a password.** Choose a long password only you know. Here, click **Fill in practice password**.
    Here, just fill in the practice one.
12. **Create the user.** Click **Create user**.

### 3. Turn off sign-up

13. **Open Auth settings.** Your account is in the list. Now make sure nobody else can make one. Click **Auth settings**.
    There's your account. Your sign-in page has no sign-up form, but that only hides it. To really stop strangers from creating accounts, turn sign-up off.
14. **Turn on Disable sign-up.** Email is the only sign-in method switched on. Click the **Disable sign-up** switch. (If Lovable already turned it on, leave it on.)
    Email is the only way to sign in, which is what you want. If Lovable already turned it on for you, just leave it on. You can still add people yourself with Add user.
15. **Save.** Click **Save**.
16. **Close More.** Click the **×** at the top right to go back to the preview.
    Close More with the X at the top right, to go back to the preview.

### 4. Sign in and look

17. **Open the page selector.** The dashboard has no link on the site. To open it in the preview, click the **page selector** above the preview (it says **Homepage**).
    The dashboard isn't linked from the site, on purpose. To open it in the preview, click the page selector above the preview, where it says Homepage.
18. **Go to Admin.** Your app's pages are listed. Click **Admin** (/admin).
    Here are all the pages in your app.
19. **Enter your email.** You're not signed in, so it sent you to the sign-in page. Type **jess@example.com**
    You're not signed in yet, so the page sent you to the sign-in page instead. That's exactly what should happen to everyone else.
20. **Enter your password.** Click **Fill in practice password**.
    Fill in the practice password.
21. **Sign in.** Click **Sign in**.

### 5. Improve it by chatting

22. **Click the chat box.** Nine requests this week, a chart by service and every request with its status. Now add a way to mark who you've called. Click **Ask Lovable...**
    There's your dashboard: nine requests this week, a chart showing which services people want, and every request with its status. These are the real requests from your live site's form, because the preview and the published site share one database. One thing is missing: a way to mark who you've already called.
23. **Ask for one change.** Ask for a button and a filter. Paste in the request.
    Ask for one small change at a time. Here: a Mark as contacted button on new requests, and a filter for the status.
    ```text
    On the admin dashboard, add a "Mark as contacted" button to every request that is still New. It should change that request's status to Contacted. Above the table, add a status filter: All, New, Contacted.
    ```
24. **Send it.** Click the **send arrow**.
25. **Mark a request as contacted.** Say you just called Dana about her color appointment. On her row, click **Mark as contacted**.
    Now try it. Say you just called Dana about her color appointment. On her row, click Mark as contacted.
26. **Show only new requests.** Her status is **Contacted** and the new count went down. Click **New** in the filter.
    Her status changed to Contacted, and the count of new requests went down.

### 6. Check the rules and publish

27. **Open More.** Dana is gone from the list. Before you publish, check who is allowed to read these requests. Click **More**.
    Dana is off the list. Before you publish, check the rules that decide who can read these requests.
28. **Open Cloud.** Click **Cloud**.
29. **Open booking_requests.** Click **booking_requests** under Database.
30. **Open RLS policies.** All the requests are here. The new **status** column is at the far right (scroll the table sideways to see it). Click **RLS policies** at the top right.
    Here are all the requests, the same ones your dashboard shows. The new status column is at the far right of the table.
31. **Close More.** Visitors can still only add a request. Only signed-in users can read or update requests, and sign-up is off. Click the **×**.
    Three rules now. Visitors can still only add a request. Only signed-in users can read requests or change their status, and since sign-up is off, the only account that can sign in is yours. The database itself enforces this, not just the page. Close More.
32. **Open Publish.** Click **Publish**.
    Now put it live.
33. **Publish changes.** The quick security scan checks your access rules and found nothing. Click **Publish changes**.
    The quick security scan checks your access rules too, and it found nothing.
34. **Open your live site.** Your update is live. Click the link.
    It's live. Your site looks the same to customers. The dashboard is at slash admin on this address, behind your sign-in.

## Frequently asked questions

**Can Lovable build a dashboard from my database?**

Yes. If your app uses Lovable Cloud, describe the page in the project chat and name the table it should read, for example a table of form submissions. Lovable builds the cards, charts and tables from that data. Test it in the preview, then publish.

**How do I add a login to my Lovable app?**

Ask Lovable in the project chat to add login, for example with email and password, and to require it before the page you want to protect. Lovable builds the sign-in page and connects it to Lovable Cloud. You manage accounts under More, then Cloud, then Users, and sign-in options under Auth settings.

**How do I stop other people from signing up to my Lovable app?**

Under More, then Cloud, then Users, click Auth settings and turn on Disable sign-up. Existing users can still sign in, and you can add people yourself with Add user, then Create new user.

**Is this course really free?**

Yes. Stepthrough is completely free, and the practice copy needs no accounts. To build it for real you need your own Lovable account, and each chat message uses Lovable credits.

[Start this module free](https://learn.ynteractive.com/modules/lovable-dashboard)

- Previous in Build Apps with Lovable: [Add an AI Chatbot to Your Website with Lovable AI](https://learn.ynteractive.com/content/lovable-ai-chatbot-website)
- Next in Build Apps with Lovable: [Publish Your Lovable Site and Connect Your Own Domain](https://learn.ynteractive.com/content/lovable-custom-domain)

## More in Build Apps with Lovable

- [Build a Landing Page with Lovable from One Prompt](https://learn.ynteractive.com/content/lovable-landing-page-from-one-prompt): Describe a small business website in one prompt, let Lovable build it, then change it by chatting, by pointing at the page and by typing on it. Undo a change from…
- [Add a Contact Form That Saves to a Database in Lovable](https://learn.ynteractive.com/content/lovable-contact-form-database): Add a booking request form to a small business site by chatting, turn on Lovable Cloud (Lovable's built-in backend, built on Supabase), send a test request and find it…

[All 5 modules in Build Apps with Lovable](https://learn.ynteractive.com/content/course/build-apps-with-lovable)

## More Lovable tutorials

- [Lovable + n8n: Build a Web App with an AI Backend](https://learn.ynteractive.com/content/lovable-n8n-web-app-ai-backend): Build a contact form in Lovable and connect it to an n8n workflow — webhook trigger, AI Agent, Google Sheets, Gmail, and a Respond node that ties it all together.
- [Build an AI Service Request Form for Your HVAC Company](https://learn.ynteractive.com/content/hvac-service-request-form-ai-lovable-n8n): Build a service request form in Lovable for Cedar Ridge Heating & Air and connect it to n8n — the AI agent sorts each job into repair, maintenance, install or…
- [Build an AI Quote Request Form for Electrical Contractors](https://learn.ynteractive.com/content/electrical-quote-request-form-ai-lovable-n8n): Build a quote request form in Lovable and connect it to an n8n workflow — webhook trigger, an AI Agent that drafts an initial estimate note, Google Sheets, Gmail, and a…
- [Build an AI Emergency Request Form for Your Plumbing Company](https://learn.ynteractive.com/content/plumbing-emergency-request-form-ai-lovable-n8n): Build an emergency service-request form in Lovable and connect it to an n8n workflow — webhook trigger, AI Agent that prioritizes the job, Google Sheets, Gmail, and a…
- [Build an AI Demo Request Form That Qualifies Leads](https://learn.ynteractive.com/content/ai-demo-request-form-lead-qualification): Build a "Book a demo" form in Lovable for Northwind Scheduling Software and connect it to n8n — the AI agent rates each lead hot, warm or nurture, saves it to Google…
- [Build a Lead Magnet Signup Form with an AI Welcome Email](https://learn.ynteractive.com/content/lead-magnet-signup-form-ai-welcome-email): Build a "Get the free guide" signup form in Lovable for Harbor & Pine Coffee Roasters and connect it to n8n — the AI agent tags each lead by interest, saves it to…

## Terms in this lesson

Plain-English definitions, each with an example from a free lesson.

[Frontend and backend](https://learn.ynteractive.com/content/glossary/frontend-vs-backend)

[The full AI glossary](https://learn.ynteractive.com/content/glossary)

## Browse related tutorials

[Build Apps with Lovable (5)](https://learn.ynteractive.com/content/course/build-apps-with-lovable) · [Lovable tutorials (13)](https://learn.ynteractive.com/content/tool/lovable)
