Steps: Set Up Access Rule Security
With the access rule security structure, user profiles and groups, permissions, and rules work with various settings to protect data. Manage these settings in the sheets, accounts, levels and versions.
Access rules
define specific intersections of data that users or groups can edit or view.If your instance uses level-based security, go to Steps: Set Up Level-Based Security.
Prerequisites
Required permissions:
Prerequisites
- Admin Access > Users
- Admin Access > Permission Sets
- Model Management Access > Model
- Model Management Access > Organization Structure
- Model Management Access > Versions
Navigation
Go to various areas of your instance, explained in each step.Basic Steps
| Administration
|
| Version Settings
|
| Level Settings
|
| Sheet and Account Settings
|
New Instances
New instances come with at least:
- User:admin@instancecode.com.
- Permission set:Full Seatcomes with most of the available permissions and it's assigned to the admin user.
- User group:Level Ownersgroup. Add new users to this group to quickly set up their access.
- 2 access rules: 1 rule grants admin@instancecode.com edit access to all the model's data. 1 grants any user in theLevel Ownersgroup edit access to all owned levels.
To preserve access to the model and data, don't change or delete the
Full Seat
permission set or the access rule for admin@instancecode.com.Set Up Admin Access for New Users
To give users full access to the model:
- Create user profile and password and assign the user theAdminpermission set. Go toAdministration>Users.
- Copy the rule for the admin user and assign it to any additional admin users. Go toAdministration>Access Rules.
Set Up Quick Level Access for New Users
- Create user profiles and passwords. Go toAdministration>Users.
- Create permission sets and assign to users. Go toAdministration>Permission Sets.
- Add the users to theLevel Ownergroup. Go toAdministration>Global User Groups.
- Assign the users level ownership. Go toAdministration>Associations.
You don't need to create rules for the users because your instance comes with a rule for the
Level Owners
group. This rule gives the users in the group edit access to all data in their owned levels.Set Up Basic View Access
To allow users to view data:
- Create user profile and password. Go toAdministration>Users.
- (Optional best practice) Create a view only group and add the new user to the view only group. Go toAdministration>Global User Groups.
- Create access rules. Go toAdministration>Access Rulesand use the template to create and upload Full View access rules for the user or the view only group.
- Give the user permission to view data. Go toAdministration>Permission Sets.Assign the user a permission set with at leastAccess Sheets,Access Reports, orAccess Dashboardspermissions.
- Make the levels assigned in the access rules visible in the accessible versions. Go toModeling>Levelsand select at least one of the levels assigned to the user or group. Choose the accessible version from the Version selector drop-down and select the checkbox. See Change Level Availability.
- For users to view data on sheets: Add the level to a level assigned sheet. Go toModeling>Levelsand select the owned level. From the Sheets section, select the checkboxes next to the sheets to add the level. This adds all child levels of the level to the sheet automatically.
With these steps completed, any version that isn't hidden is visible to the new user. To check, go to
Modeling
> Versions
and look at the drop-down selection for Users. If you added the user to a group, select the group from the Group drop-down to see the Access Level below it.Set Up Edit Access to Plan Versions
To allow users to also edit plan versions, add the following:
- Give the user permission to edit data. Go toAdministration>Permission Sets.Assign a permission set with theEditable Sheet Accesspermission.
- Give the user an Edit rule. Go toAdministration>Access Rulesto update or add Edit rules to the user or group.
- Give the user edit access to the versions. Go toModeling>Versions. From the Access Controls section for Editable Sheet Access,chooseFull Access.
Or, assign them a user-assigned sheet without the Salary Detail sheet setting.
Restrict Edit Access to Actuals
If you want only certain users to edit actuals, create a specific permission set for it and refine the version access. This blocks others without the permission set from being able to edit actuals versions.
To create a privileged permission set for actuals access:
- Create a new permission set. Go toAdministration>Permission Sets>New Permission Set.For Permission Set Name, enter a name such asActuals Access, orPrivileged Access.SelectEditable Sheet AccessandPrivileged Actuals Access.Then assign the new permission set to the users who can edit actuals.
- Give only privileged users access to the actuals versions. Go toModeling>Versions. In the Access Control section of the settings for the actuals versions:
- From the Privileged Actuals Access drop-down,selectFull Access.
- For all other user type drop-downs, select any other options besidesFull Access.
- Repeat for all actuals, or at least the leaf-level actuals. Only leaf-level actuals are editable. Leaf level actuals are actuals without sub-versions that roll up to it.
- Make the actuals versions available. Go toModeling>Levels. For levels assigned to the users, choose any leaf-level actuals version from the Version Selector drop-down. Select the checkbox.
Now only users with this new permission set can edit the actuals versions available in the levels they can access.
To make an existing administration permission set the only one that allows actuals edit :
- Go toAdministration>Permission Setsand selectEditnext to the administrator permission set. SelectModel>VersionandEditable Sheet Accessand save.
- Go toModeling>Versions. For only the Admin user type, selectFull Accessin each leaf level actuals version.
Now only users with the administration permission set can edit the actuals versions.
Refine View and Edit Access
- Create Limited View access rules: The user or group can't view splits.
- Use Salary Detail settings: Make an account's details or modeled sheet viewable and editable to only users who have the Access Salary Detail permission.
- Hide or lock accounts on standard sheets: To hide, go toModeling>Level Assigned Sheets. Select a standard sheet and selectCustomization for Sub-Levels. To lock, select the sheet and selectAccount Groups. Select an account from the left box. Select theRead Onlycheckbox on the right. See Steps: Build Standard Sheets.
- Use cube restrictions: Hide intersections of data in a cube sheet for all users. See Concept: Cube Sheet Building.