Example: Enable Segment-Based Security for Student Expenses
This example illustrates how to enable workers to manage only student expense data by configuring segment-based security.
Your university manages expenses on behalf of nonworkers, including matriculated students. You want to enable a subset of workers to:
- Create and submit expense reports on behalf of only matriculated students.
- View expense data only for matriculated students to run custom and standard reports.
- Assign the workers that you want to access student expense data to:
- AStudent Expense Administrator (Constrained)security group.
- The relevant roles and academic units.
- Configure theExpense Report Eventbusiness process and security policy in the Expenses functional area. See: Steps: Configure Business Process Definitions.
- Security: These domains in the Student Core functional area:
- Student Data: Student ID
- Student Data: Student Profile
- Access theCreate Security Grouptask.
- On theType of Tenanted Security Groupprompt, selectSegment-Based Security Group.
- In theNamefield, enterStudent Expenses Only.
- ClickOK.
- On theSecurity Groupsprompt, selectStudent Expense Administrator (Constrained).
- On theAccess to Segmentsprompt, selectStudent Expense Payee Type Segment.
- ClickOK.
- From the related actions menu of the segment-based security group, select .
- On theDomain Security Policies permitting View accessprompt, selectProcess: Expense Reports.
- ClickOKandDone.
- From the related actions menu of theExpense Report Eventbusiness process, select .
- On theSecurity Groupsprompt in theCreate Expense Report for Non-Workersection, selectStudent Expenses Only.
- ClickOKandDone.
- Access theActivate Pending Security Policy Changestask.
- In theCommentfield, enterRestricting workers to only student expense data.
- ClickOK.
- Select theConfirmcheck box.
- ClickOK.
Add expense payments on payment elections for matriculated students, or enable these students to manage their own payment elections.
Reassign credit card transactions to matriculated students manually to include these transactions on student expense reports.