Steps: Create Access Rules
Prerequisites
Documentation to read:
- The template uses hierarchy logic for every secured dimension. See Concept: Hierarchies and Access Rules.
- Access to data depends on various access controls throughout the model. For start-to-finish instructions, see Steps: Set Up Access Rule Security.
- For best practices, see Reference: Access Rules and Your Model.
- When you are transitioning from the legacy level-based security, see Transition to Access Rules.
Actions to complete:
- Complete your model's structure, including the levels, accounts, attributes and custom dimensions.
- Have your level, level attributes, account, and custom dimension hierarchies viewable as you create rules. You need codes for levels, dimension values, and attribute values. For all accounts except modeled accounts, you need the account code. For modeled accounts, you need the sheet name.
- When you use associations for rules, have all associations completed and have the codes viewable as you create the rules.
- Create the users and groups.
- Security:Userspermission.
When you have a lot of users, or often add new users, create rules for user groups. Then add each user to a group to immediately grant them appropriate access. Update the rule per group to update the access of all the users in the group.
Context
Access rules provide users access to the data in the model.
With access rules, you can secure levels, accounts, attributes, and custom dimensions. You then use secured dimensions to define specific intersections of data that users or groups can edit or view.
You use a spreadsheet template to create the rules. You can either replace all existing rules with the template or update and append the rules.
Access rules describe specific intersections of dimensions in your model. When a user's rules conflict with each other at a specific intersection, the access defaults to the more permissive rule.
Steps
- Optional. Make Custom Dimensions Eligible for Access Rules. If you plan to secure custom dimensions, you might need to change their settings.
- SelectAdministrationfrom the main menu.
- ClickAccess Rules.
- Secure Dimensions and Attributes for Access Rules. You use the dimensions and attributes to define access rules.
- Add Rules to the Access Rule Spreadsheet. Complete the template or make changes to the exported rules. You build the user's access by permitting more with each rule. You can also create rules based on owned levels, associations, and attribute tags.
- Review the access rules on the table.
Periodically audit your rules when you make changes to the model, such as adding new levels, reorganizing any hierarchy, or deleting dimension values.
Delete Access Rules
- From the toolbar, selectExport.
- Open the file and delete rules from the spreadsheet. Don't make any other changes to the other rules.
- Save the spreadsheet.
- Return to the access rules page.
- From the toolbar, selectImport.
- Select theReplace Allradio button.
- Select theReplace Allbutton to confirm. The template has all the rules that you didn't want to delete.
- SelectDonewhen you see the success message.
Audit and Correct Invalid Access Rules
When you update your model, associated rules automatically update according to the hierarchy.
Change to Model | Effect on Rules |
|---|---|
Create or reparent accounts, levels, or dimension values |
|
Delete accounts or levels | We remove the deleted items from the rule. When it's the only item that was listed, we delete the rule. When the deleted rule was the only rule assigned to you, you also lose access to all data. |
Delete dimension values |
|
To find and correct invalid access rules:
- Go toAdministration>Access Rules.
- ClickExport.
- Save the file and don't make any changes to any rules.
- From the access rules screen, clickImport.
- Drag and drop the exported file into the box.
- If there are any invalid rules, you get an error with a link to the error report. Use the report to correct any errors in the rules and import again.