Calculate the Access of Users
The user access calculator can help you understand a user's access based on the access
rules and version access settings.
Prerequisites
Prerequisites
Security:
Users.
Navigation
From the nav menu, go to Administration
> User
Access Calculator
.Dimension Lists
There's a list for
Levels
, Accounts
, Versions
, and each custom
dimension in your model, regardless of whether or not you secured them for access
rules.Before clicking
Calculate
, you must:- Select a version to calculate the version access controls for the user, which supersedes access rules.
- Select a value from each secured dimensions. This calculates the access rules.
- Select any other dimension values that aren't secured. This could include accounts and any custom dimensions. This has no affect, but is still required to proceed.
Check Access to a Coordinate
With this method, the calculator tells you what kind of access the user has to a
particular coordinate.
- Select a username from theUserdrop-down list.
- Click a value from each of the lists.
- ForMode, clickSingle Coordinate.
- ClickCalculate.
The pop-up window describes the access of the user.
Check Access to a Single Dimension
With this method, the calculator tells you what values the user has some access to
for the specific dimension. From here you can pivot your calculations to get the
specific coordinates.
- Select a username from theUserdrop-down list.
- ForMode, clickSingle Dimension.
- From theSingle Dimensionprompt that appears, select the dimension you want to calculate. Example: SelectAccountif you want to see all the accounts the user can access somewhere.
- Click a value from each of the dimension lists. Selecting dimensions from the list that you're searching, has no affect, but is still required. Example: If you selectedAccountfrom the prompt, you must click some account from the account list. The results still show all the accounts the user can access.
- ClickCalculate.
The pop-up window shows a table. In the
Name
column is a list of all the
values the user has access to for the single dimension you selected from the prompt.
Example: If you selected Account,
you see a list of all the accounts the user
has access to at some intersection in the Name
column. In the Access
column you see what type of access the user has to the account at the other
coordinates you selected from the lists. Example: Pivot Single Dimension Calculations
Example: Your model secures levels and accounts.
Level Structure | Account Structure |
|---|---|
HQ
|
|
Your level structure:
You want to figure out User1's access.
- Find Any Accessible Levels
- SelectUser1from theUserdrop-down list.
- ClickSingle Dimensionand selectLevelfrom theSingle Dimensionprompt.
- Click any level from level list, and any version from the version list.
- ClickRevenuefrom the account list.
The results are:NameAccessSalesNoneMarketingNoneYou see that the user has- Some kind of access to 2 levels in the entire model: Sales and Marketing.
- No access to either level at the Revenue account.
- Find Accessible Accounts at the Sales Level
- Your next step is to find the accessible coordinate for those 2 levels. You could:
- Click through the account list and recalculate for each account.
- Pivot your search.
To pivot:- SelectAccountsfrom theSingle Dimensionprompt because you already know all the levels User1 can access.
- From the level list,clickSalesbecause you already know User1 has access toSales.
- Leave the other list selections as-is.
- ClickCalculate.
The results are:NameAccessExpenseWriteInventoryReadYou now know User1's access at the Sales level and all the accounts the user can access at some level:- Access only 2 accounts in the entire model at some level: Expense and Inventory.
- Change data at Expense and view data at Inventory for the Sales level.
- Find Accessible Accounts at the Marketing Level
- ClickMarketingfrom the level list.
- Leave everything else as-is.
The results are:ExpenseWriteInventoryNoneYou now see that at the Marketing level User1 has only change data in 1 account, Expense.You now know all User1's access:- Change data in Expenseat the Salesand Marketinglevels
- View Inventoryat the Saleslevel.
Access Calculation Results
The resulting access is a combination of both access rules and version access
controls. Version access control are defined in the version settings. Version access
controls supersede access rules.
Calculator Results | Meaning | Reasons |
|---|---|---|
WRITE
| Can add and change data, splits, modeled sheet rows, and
details. Can add cell notes. | BOTH:
|
READ_EXCEPT_NOTES
| Can view data, splits, modeled sheet rows, and details. Can add notes. | BOTH:
OR BOTH:
OR BOTH:
OR BOTH:
|
READ
| Can view data, splits, modeled sheet rows, and details. Can't add notes. | BOTH:
OR BOTH:
|
READ_NOSPLITS_WRITENOTES
| Can't view splits, modeled sheet rows, or details. Can add cell notes. | BOTH:
OR BOTH:
OR BOTH:
|
READ_NOSPLITS
| Can view data. Can't view splits, modeled sheet rows, or details. Can't add cell notes. | BOTH:
|
NONE
| Can't view or change data. | EITHER:
|
IMPORT_AND_NOTES
| Can change data only through imports. Can view the data, splits, modeled sheet rows, and details. Can add notes. | BOTH:
|