Steps: Maintain Access to Ledger Accounts
- Understand segment-based security groups and segmented security.
- Determine how you want to control access to ledger account for groups of workers.
- Security:Set Up: Ledger Account Security Segmentsdomain within theSegmented Setupfolder in the System functional area. See Steps: Set Up Security Permissions.
You can configure segment-based security to restrict availability of ledger accounts to members of designated security groups.
Workers see only the ledger accounts to which they have access when:
- Performing accounting journal transactions (except recurring journals).
- Running ledger account, trial balance, journal, financial metrics, and manager metrics reports.
Once you enable ledger account segmentation, a ledger account will only be visible if associated to a ledger account segment.
- Access theCreate Ledger Account Security Segmenttask.Select the ledger accounts to include in the segment. You can include:
- Individual Ledger Accounts.
- All accounts in a Ledger Account Summary.
- All accounts of a Ledger Type.
Create enough segments to cover each unique security access requirement. Included values can cross multiple segments or be mutually exclusive. Workday recommends that you build segments from least to most restrictive.Security:Set Up: Ledger Account Security Segmentsdomain within theSegmented Setupfolder in the System functional area. - (Optional) Access theCreate Security Grouptask.Create the security groups to associate with the security segments if existing security groups don't meet your business requirements.
- Access theCreate Security Grouptask.
- SelectSegment-Based Security GroupforType of Tenanted Security Groupand enter a name for the security group.
- Under theGroup Criteriasection, select the desired security group.
- Under theAccess to Segmentssection, add the ledger account security segment that you created in Step 1.
See also Create Segment-Based Security Groups. - Edit Domain Security Policies.To enforce your ledger account segment security policy in transactions and reporting:
- Access theDomain Security Policies for Functional Areareport.
- Select theCommon Financial ManagementFunctional Area.
- Select theAccess Ledger Account (Segmented)security policy from the hierarchy.
- Remove theAll Usersdefault security group.
- Add the desired security groups.You can include your ledger account segment-based security groups to restrict its members to the values included in their security segments.
- Activate Pending Security Policy Changes.
- Test the security policy changes.For each security segment, sign in as a user of the associated segment-based security group. Then verify that you can only access the ledger accounts for that segment.
Workers can:
- Create journals with only the ledger accounts that they have access to.
- Edit journals only if they have access to all the ledger accounts in the journal.
- View journals as long as they have access to one of the ledger accounts in the journal lines.If a journal has lines for ledger accounts they don't have access to, they can view the whole journal, but can't take any actions against it.
- Run journal line and ledger account reports for only the ledger accounts that they have access to.
- Run custom and standard financial reports that include journal lines only for the ledger accounts they have access to.
Restrict expense accountants to see the ledger accounts for expense reports that are payable to a worker but not a supplier.