diff --git modules/dashboard/dashboard.info modules/dashboard/dashboard.info
index 74f41e6..29eaef6 100644
--- modules/dashboard/dashboard.info
+++ modules/dashboard/dashboard.info
@@ -6,4 +6,5 @@ package = Core
 version = VERSION
 files[] = dashboard.module
 dependencies[] = block
+files[] = dashboard.test
 configure = admin/dashboard/customize
diff --git modules/dashboard/dashboard.module modules/dashboard/dashboard.module
index ecd9fa5..5c7ef41 100644
--- modules/dashboard/dashboard.module
+++ modules/dashboard/dashboard.module
@@ -235,13 +235,35 @@ function dashboard_admin($launch_customize = FALSE) {
 }
 
 /**
- * Returns TRUE if the user is currently viewing the dashboard.
+ * Determines if the dashboard should be displayed on the current page.
+ *
+ * This function checks if the user is currently viewing the dashboard and has
+ * access to see it. It is used by other functions in the dashboard module to
+ * decide whether or not the dashboard content should be displayed to the
+ * current user.
+ *
+ * Although the menu system normally handles the above tasks, it only does so
+ * for the main page content. However, the dashboard is not part of the main
+ * page content, but rather is displayed in special regions of the page (so it
+ * can interface with the Block module's method of managing page regions). We
+ * therefore need to maintain this separate function to check the menu item for
+ * us.
+ *
+ * @return
+ *   TRUE if the dashboard should be visible on the current page, FALSE
+ *   otherwise.
+ *
+ * @see dashboard_block_info_alter()
+ * @see dashboard_page_build()
  */
 function dashboard_is_visible() {
   static $is_visible;
   if (!isset($is_visible)) {
+    // If the current menu item represents the page on which we want to display
+    // the dashboard, and if the current user has access to see it, return
+    // TRUE.
     $menu_item = menu_get_item();
-    $is_visible = isset($menu_item['page_callback']) && $menu_item['page_callback'] == 'dashboard_admin';
+    $is_visible = isset($menu_item['page_callback']) && $menu_item['page_callback'] == 'dashboard_admin' && !empty($menu_item['access']);
   }
   return $is_visible;
 }
diff --git modules/dashboard/dashboard.test modules/dashboard/dashboard.test
new file mode 100644
index 0000000..bbc3050
--- /dev/null
+++ modules/dashboard/dashboard.test
@@ -0,0 +1,56 @@
+<?php
+// $Id$
+
+/**
+ * @file
+ * Tests for the dashboard module
+ */
+
+class DashboardTestCase extends DrupalWebTestCase {
+  
+  public static function getInfo() {
+    return array(
+      'name' => 'Dashboard functionality',
+      'description' => 'Test access control to dashboard',
+      'group' => 'Dashboard',
+    );
+  }
+
+  function setUp() {
+    parent::setUp();
+
+    // Create and log in an administrative user having access to the dashboard.
+    $admin_user = $this->drupalCreateUser(array('access administration pages', 'administer blocks'));
+    $this->drupalLogin($admin_user);
+    
+    theme_enable(array('stark'));
+    variable_set('theme_default', 'stark');
+    variable_set('admin_theme', 'stark');
+  }
+
+  /**
+   * Test adding a block to the dashboard and checking access to it.
+   */
+  function testDashboardAccess() {
+
+    // Add a new custom block to a dashboard region.
+    $custom_block = array();
+    $custom_block['info'] = $this->randomName(8);
+    $custom_block['title'] = $this->randomName(8);
+    $custom_block['body[value]'] = $this->randomName(32);
+    $custom_block['regions[stark]'] = 'dashboard_main';
+    $this->drupalPost('admin/structure/block/add', $custom_block, t('Save block'));
+
+    // Ensure admin access.
+    $this->drupalGet('admin');
+    $this->assertResponse(200, t('Admin has access to the dashboard.'));
+    $this->assertRaw($custom_block['title'], t('Admin has access to a dashboard block.'));
+
+    // Ensure non-admin access is denied.
+    $normal_user = $this->drupalCreateUser();
+    $this->drupalLogin($normal_user);
+    $this->drupalGet('admin');
+    $this->assertResponse(403, t('Non-admin has no access to the dashboard.'));
+    $this->assertNoText($custom_block['title'], t('Non-admin has no access to a dashboard block.'));
+  }
+}
