Skip to main content
Adaptive Planning
Laatst bijgewerkt: 2023-06-23
Steps: Set Up Level-Based Security

Steps: Set Up Level-Based Security

With the level-based security structure, user profiles, permissions, various access controls, and settings work together to protect data. Manage these settings and controls in sheets, accounts, levels, and versions.
If your instance uses access rule security, go to Concept: Access Rules and Steps: Set Up Access Rule Security.

Navigation

Navigation Icon5.png Go to various areas of your instance, explained in each step.

Prerequisites

Required permissions:
  • Admin Access > Users
  • Admin Access > Permission Sets
  • Model Management Access > Model
  • Model Management Access > Organization Structure
  • Model Management Access > Versions

Level-Based Security Structure

IDandPassword.png
Administration
Version Access.png
Version Settings
LevelOwner.png
Level Settings
  • Set level availability for each version. See Change Level Availability.
  • (optional for sheet access) Assign owned levels to sheets.
SheetSettings.png
Sheet and Account Settings
  • Sheet Settings: Read only accounts, sub-level customization, cube restrictions, and Salary Detail.
  • Account Settings: Data privacy and Salary Detail. See Steps: Protect Sensitive Data.

Set Up Basic View Access

To allow users to view data:
  1. Create user profile and password. Go to
    Administration
    >
    Users
    .
  2. Give the user permission to view data. Go to
    Administration
    >
    Permission Sets.
    Assign the user a permission set with at least
    Access Sheets
    ,
    Access Reports
    , or
    Access Discovery
    permissions.
  3. Give the user access to the versions. Go to
    Modeling
    >
    Versions
    . Choose
    Locked
    ,
    Locked Except Notes
    , or
    Visible
    for the
    Users
    drop-down.
  4. Give the user ownership to levels. Go to
    Administration
    >
    Users
    .
  5. Make the level visible in the accessible versions. Go to
    Modeling
    >
    Levels
    and select the owned level. Choose the accessible version from the version selector drop-down and select the checkbox.
  6. For users to view data on sheets, add the level to a level-assigned sheet. Go to
    Modeling
    >
    Levels
    and select the owned level. From the
    Sheets
    section, select the checkboxes next to the sheets to add the level. This adds all child levels of the level to the sheet automatically.

Set Up Basic Edit Access to Plan Versions

To allow users to edit data, add the following:
  1. Give the user permission to edit data. Go to
    Administration
    >
    Permission Sets.
    Click
    Edit
    for the permission set and select
    Editable Sheet Access
    .
  2. Give the user edit access to the versions. Go to
    Modeling
    >
    Versions
    . From the
    Access Controls
    section for Editable Sheet Access,
    choose
    Full Access
    .
Or, assign them a user-assigned sheet without the Salary Detail sheet setting.

Restrict Basic Edit Access to Actuals

If you want only certain users to edit actuals, create a specific permission set for it and refine the version access. This blocks others without the permission set from being able to edit actuals versions.
To create a privileged permission set for actuals access:
  1. Create a new permission set. Go to
    Administration
    >
    Permission Sets
    >
    New Permission Set.
    For Permission Set Name, enter a name such as
    Actuals Access
    , or
    Privileged Access
    .
    Select
    Editable Sheet Access
    and
    Privileged Actuals Access.
    Then assign the new permission set to the users who can edit actuals.
  2. Give only privileged users access to the actuals versions. Go to
    Modeling
    >
    Versions
    . In the
    Access Control
    section of the settings for the actuals versions:
    1. From the
      Privileged Actuals Access
      drop-down,
      select
      Full Access
      .
    2. For all other user type drop-downs, select any other options besides Full Access.
    3. Repeat for all actuals, or at least the leaf-level actuals. Only leaf-level actuals are editable. Leaf level actuals are actuals without sub-versions that roll up to it.
  3. Make the actuals versions available. Go to
    Modeling
    >
    Levels
    . For levels owned by the users, choose any leaf-level actuals version from the Version Selector drop-down. Select the checkbox.
Now only users with this new permission set can edit the actuals versions available in the levels they can access.
To make an existing administration permission set the only one that can edit actuals:
  1. Go to
    Administration
    >
    Permission Sets
    and select
    Edit
    next to the administrative permission set. Select
    Model
    >
    Version
    and
    Editable Sheet Access
    and save.
  2. Go to
    Modeling
    >
    Versions
    . For only the Admin user type of each leaf level actuals version, select
    Full Access
    .
Now only users with the administrative permission set can edit the actuals versions.

Refine View and Edit Access

  • Use Salary Detail settings: Make an account's details or a modeled sheet viewable and editable to only users who have the Access Salary Detail permission.
  • Hide or lock accounts on standard sheets: To hide, go to
    Modeling
    >
    Level Assigned Sheets
    . Select a standard sheet and select
    Customization for Sub-Levels
    . From the selection box on the left, select an account. Uncheck levels and sub-levels in the selection box on the right. You hide the account data for unchecked levels in that sheet for users who have access to only those levels. To lock, select the sheet and select
    Account Groups
    . Select an account from the left box. Select the
    Read Only
    checkbox on the right.
  • Use cube restrictions: Hide intersections of data in a cube sheet for all users. See Concept: Cube Sheet Building.