Concept: Level Ownership
Level ownership is a type of association. It gives users special privileges throughout the model. If you use level-access security, level ownership also controls your access to data.
You can manage level ownership in the
Associations
or Users
area of Administration
. Level ownership trickles down the level hierarchy. Users who own a parent level own the child levels, the child of each child level, and so on.Special Privileges
Level owners have special privileges for the levels that they own, regardless of their security configuration. As a level owner, you can:
- Approve levels in workflow.
- Assign level ownership to other users.
- Create and view journal entries on levels that you own.
- Manage owned levels from the modeling menu.
- Receive shared-by-level reports in yourShared Reportsfolder.
- Review Intercompany Eliminations debits and credits for owned levels if you have Consolidation.
Access to Data
If your instance uses level-based security, level ownership determines how you control access to data. With the appropriate security permissions, in addition to the special privileges, you can:
- Access data if you own at least 1 level of data.
- Open level-assigned sheets assigned to the levels that you own.
- View the data of the level in charts and reports.
Even without level ownership, you can still view the level when:
- You have theOrganization Structure>All Levelspermission. You can change the level settings from the level hierarchy. You can't view the data associated with the levels in sheets and reports.
- Your user-assigned sheets include the level. You can enter and change the data within the level.
- You change modeled sheets with level columns and split the row. You can select any level from the drop-down prompt in the cell and enter or change data.
- You use formula assistant or explore cells for accounts with aPublic at all levelsprivacy setting. You can select levels you don't own in the level drop-down prompt, reference that account from any level, and drill into the source data of the level.
- You have theData Designerpermission. You can view all the levels in the Integration.
- You view a shared report or a shared global report snapshot that includes the level.
Using Level Ownership for Access Rules
You can define access rules with owned levels using the tilde. Then, you can grant access to a large number of users with these dynamic rules. Example: For a user group, you can create a rule for a user group that grants access to all owned levels. Every user in the group gets access to all their owned levels. When you change the user's owned levels, you don't need to change the rule because it dynamically honors the user's current owned levels.