Example: Set Up Access for Executives
Use permissions and access rules to set up the typical access required for executive-type roles.
Create the permission set and user profile for the CEO of your company. Like most executives, the CEO must:
- Build reports and dashboards.
- View sheets, but not edit the data.
- View all the data, including rollup data of salaries.
- Not view the salary details of individual employees stored on thePersonnelmodeled sheet.
- View salary rollups as an expense for the company.
Information about the model:
General Ledger | Personnel Modeled Sheet |
|---|---|
Expenses
Revenue
|
|
To set up the CEO, you must:
- Limit their permissions to sheets, reports, and dashboards.
- Grant full view access to all data, while protecting the salary details on thePersonnelmodeled sheet.
- Save the access rule spreadsheet asNew Access Rules.
- Security:
- Userspermission.
- Permission Setspermission.
- SelectAdministrationfrom the main menu.
- ClickPermission Sets.
- ClickNew Permission Set.
- As you complete the form, consider:
Opción Descripción Permission Set NameEnterExec Role.Set Using TemplateClickView Only.Additional permissions to select- UnderAccess Reports, check any sub-permissions without check marks.
- UnderAccess Dashboards, check any sub-permissions without check marks.
- Keep theSalary Detailpermission selected because the access rules that you create prevent access to the details on the sheet.
- ClickSubmit.This permission set enables executives to access sheets, OfficeConnect, web reports, and dashboards.
- From the breadcrumbs, clickAdministration.
- ClickUsers.
- ClickNew User.
- As you complete the form, consider:
Opción Descripción NameEnterCEO.UsernameEnterceo@company.com.Password and Re-enter PasswordEnter anything.Permission SetSelectExec Role. - ClickSubmit.
- From your computer files, open theNew Access Rulesspreadsheet.
- As you complete the columns of the next blank row, consider:
Opción Descripción Access TypeEnterFull View.UsernameEnterceo@company.com.LevelEnter(+)to give the CEO access to all levels.Account (Grant All Except)EnterPersonnelto exclude all accounts in thePersonnelsheet. The CEO can still view theSalaryaccount in the general ledger. This general ledger account displays the total expense of salaries per level, but not the details of each employee.Product (Grant)Enter(+)to grant the CEO access to all dimension values of theProductdimension. - Save the spreadsheet.
- Return .
- From the toolbar, clickImport.
- SelectUpdate and Append.
- Click the cloud to upload theNew Access Rulesspreadsheet from your computer folders.
- ClickDone.The rule enables the CEO to view all accounts, except the salary details of the Personnel sheet.