Skip to main content
Adaptive Planning
Steps: Create Access Rules

Steps: Create Access Rules

Prerequisites

Documentation to read:
Actions to complete:
  • Complete your model's structure, including the levels, accounts, attributes and custom dimensions.
  • Have your level, level attributes, account, and custom dimension hierarchies viewable as you create rules. You need codes for levels, dimension values, and attribute values. For all accounts except modeled accounts, you need the account code. For modeled accounts, you need the sheet name.
  • When you use associations for rules, have all associations completed and have the codes viewable as you create the rules.
  • Create the users and groups.
  • Security:
    Users
    permission.
When you have a lot of users, or often add new users, create rules for user groups. Then add each user to a group to immediately grant them appropriate access. Update the rule per group to update the access of all the users in the group.

Context

Access rules provide users access to the data in the model.
With access rules, you can secure levels, accounts, attributes, and custom dimensions. You then use secured dimensions to define specific intersections of data that users or groups can edit or view.
You use a spreadsheet template to create the rules. You can either replace all existing rules with the template or update and append the rules.
Access rules describe specific intersections of dimensions in your model. When a user's rules conflict with each other at a specific intersection, the access defaults to the more permissive rule.

Steps

  1. Optional. Make Custom Dimensions Eligible for Access Rules. If you plan to secure custom dimensions, you might need to change their settings.
  2. Select
    Administration
    from the main menu.
  3. Click
    Access Rules
    .
  4. Secure Dimensions and Attributes for Access Rules. You use the dimensions and attributes to define access rules.
  5. Add Rules to the Access Rule Spreadsheet. Complete the template or make changes to the exported rules. You build the user's access by permitting more with each rule. You can also create rules based on owned levels, associations, and attribute tags.
  6. Review the access rules on the table.
Periodically audit your rules when you make changes to the model, such as adding new levels, reorganizing any hierarchy, or deleting dimension values.

Delete Access Rules

  1. From the toolbar, select
    Export
    .
  2. Open the file and delete rules from the spreadsheet. Don't make any other changes to the other rules.
  3. Save the spreadsheet.
  4. Return to the access rules page.
  5. From the toolbar, select
    Import
    .
  6. Select the
    Replace All
    radio button.
  7. Select the
    Replace All
    button to confirm. The template has all the rules that you didn't want to delete.
  8. Select
    Done
    when you see the success message.

Audit and Correct Invalid Access Rules

When you update your model, associated rules automatically update according to the hierarchy.
Change to Model
Effect on Rules
Create or reparent accounts, levels, or dimension values
  • At intersections where you can access the parent, you can also access the new child.
  • At intersections where you can't access the parent, you can't access the new child. This is true even when you can access all the siblings of the new child.
Delete accounts or  levels
We remove the deleted items from the rule. When it's the only item that was listed, we delete the rule. When the deleted rule was the only rule assigned to you, you also lose access to all data.
Delete dimension values
  • For dimension values listed in the Grant column, the rule remains valid. We update the rule to include only the uncategorized value of the dimension.
  • For dimension values listed in the Grant All Except column, we remove the deleted items from the rule. When it's the only item that was listed, we delete the rule. When the deleted rule was the only rule assigned to you, you also lose access to all data.
To find and correct invalid access rules:
  1. Go to
    Administration
    >
    Access Rules
    .
  2. Click
    Export
    .
  3. Save the file and don't make any changes to any rules.
  4. From the access rules screen, click
    Import
    .
  5. Drag and drop the exported file into the box.
  6. If there are any invalid rules, you get an error with a link to the error report. Use the report to correct any errors in the rules and import again.