跳至主要內容
Adaptive Planning
上次更新時間 :2023-06-23
Concept: Security Structure

Concept: Security Structure

Your instance uses one of 2 security structures: level-based access or access rules.

Level-Based Security

Level-based security relies on level ownership, an association. With level-based security, you can only see the data of levels you own.

Access Rules Security

Access rule security adds a flexible layer of rules that replaces level-based security. You can combine level-based security with access rules by using owned levels in the rules. These rules dynamically update when level ownership changes.
See Transition to Access Rules for information about what changes when you switch to access rules.

Credentials

Credentials are the combination of a user ID and password. To create credentials for a team member, create a user profile. As part of that process, assign them a permission set and owned levels.

Permissions

With permissions, you create various permission sets. Each permission set includes permissions that control a wide range of capabilities. You then assign the permission sets to each user to control where they can go in your model.

Access Controls

Access Rules
Access rules
define specific intersections of data that users or groups can change or view. Secured dimensions define intersections. Secured dimensions include levels, accounts, and up to 3 custom dimensions.
Levels
  • Level ownership: With access rule security, level ownership gives you special administrative privileges to levels.
  • Access rules using owned levels: Create access rules based on owned levels. This assigns users data access to all their owned levels. When you update their owned levels, the rules dynamically update too. See Create Access Rules.
  • Level availability: This level setting makes levels and their data visible in specific versions. See Change Level Availability .
Versions
Use version access controls to hide or lock the entire version for broadly defined user types. Or, lock portions of versions.
Account Settings
Use the 2 settings to control access for accounts:
  • Control how you reference account values in formulas with the Data Privacy setting. You can either reference the value at the current level only, the top level, or any level. This account setting reveals the data of other levels that you may not otherwise have access to.
  • Flag an account as a Salary Detail. Only users with the Salary Detail permission can see the account splits and details. See Steps: Protect Sensitive Data.
Sheets
  • After you add accounts to standard sheets, you can mark them as read-only and no one can change the data on that sheet. See Edit Standard Sheets.
  • You can also hide the whole sheet from sublevels.
  • For cube sheets, you can add cube restrictions that block access to specific intersection.
  • Flag a modeled sheet as Salary Detail. Only users with the Salary Detail permission can open the sheet.