Steps: Set Up Level-Based Security
With the level-based security structure, user profiles, permissions, various access controls, and settings work together to protect data. Manage these settings and controls in sheets, accounts, levels, and versions.
If your instance uses access rule security, go to Concept: Access Rules and Steps: Set Up Access Rule Security.
Navigation
Go to various areas of your instance, explained in each step.
Prerequisites
Prerequisites
See the Users and Permission Sets.
Required permissions:
- Admin Access > Users
- Admin Access > Permission Sets
- Model Management Access > Model
- Model Management Access > Organization Structure
- Model Management Access > Versions
Level-Based Security Structure
| Administration
|
| Version Settings
|
| Level Settings
|
| Sheet and Account Settings
|
Set Up Basic View Access
To allow users to view data:
- Create user profile and password. Go toAdministration>Users.
- Give the user permission to view data. Go toAdministration>Permission Sets.Assign the user a permission set with at leastAccess Sheets,Access Reports, orAccess Discoverypermissions.
- Give the user access to the versions. Go toModeling>Versions. ChooseLocked,Locked Except Notes, orVisiblefor theUsersdrop-down.
- Give the user ownership to levels. Go toAdministration>Users.
- Make the level visible in the accessible versions. Go toModeling>Levelsand select the owned level. Choose the accessible version from the version selector drop-down and select the checkbox.
- For users to view data on sheets, add the level to a level-assigned sheet. Go toModeling>Levelsand select the owned level. From theSheetssection, select the checkboxes next to the sheets to add the level. This adds all child levels of the level to the sheet automatically.
Set Up Basic Edit Access to Plan Versions
To allow users to edit data, add the following:
- Give the user permission to edit data. Go toAdministration>Permission Sets.ClickEditfor the permission set and selectEditable Sheet Access.
- Give the user edit access to the versions. Go toModeling>Versions. From theAccess Controlssection for Editable Sheet Access,chooseFull Access.
Or, assign them a user-assigned sheet without the Salary Detail sheet setting.
Restrict Basic Edit Access to Actuals
If you want only certain users to edit actuals, create a specific permission set for it and refine the version access. This blocks others without the permission set from being able to edit actuals versions.
To create a privileged permission set for actuals access:
- Create a new permission set. Go toAdministration>Permission Sets>New Permission Set.For Permission Set Name, enter a name such asActuals Access, orPrivileged Access.SelectEditable Sheet AccessandPrivileged Actuals Access.Then assign the new permission set to the users who can edit actuals.
- Give only privileged users access to the actuals versions. Go toModeling>Versions. In theAccess Controlsection of the settings for the actuals versions:
- From thePrivileged Actuals Accessdrop-down,selectFull Access.
- For all other user type drop-downs, select any other options besides Full Access.
- Repeat for all actuals, or at least the leaf-level actuals. Only leaf-level actuals are editable. Leaf level actuals are actuals without sub-versions that roll up to it.
- Make the actuals versions available. Go toModeling>Levels. For levels owned by the users, choose any leaf-level actuals version from the Version Selector drop-down. Select the checkbox.
Now only users with this new permission set can edit the actuals versions available in the levels they can access.
To make an existing administration permission set the only one that can edit actuals:
- Go toAdministration>Permission Setsand selectEditnext to the administrative permission set. SelectModel>VersionandEditable Sheet Accessand save.
- Go toModeling>Versions. For only the Admin user type of each leaf level actuals version, selectFull Access.
Now only users with the administrative permission set can edit the actuals versions.
Refine View and Edit Access
- Use Salary Detail settings: Make an account's details or a modeled sheet viewable and editable to only users who have the Access Salary Detail permission.
- Hide or lock accounts on standard sheets: To hide, go toModeling>Level Assigned Sheets. Select a standard sheet and selectCustomization for Sub-Levels. From the selection box on the left, select an account. Uncheck levels and sub-levels in the selection box on the right. You hide the account data for unchecked levels in that sheet for users who have access to only those levels. To lock, select the sheet and selectAccount Groups. Select an account from the left box. Select theRead Onlycheckbox on the right.
- Use cube restrictions: Hide intersections of data in a cube sheet for all users. See Concept: Cube Sheet Building.