Skip to main content
Administrator Guide
Last Updated: 2024-09-20
Set Up Role-Based Security Reporting

Set Up Role-Based Security Reporting

Security:
Customer Central Security Administration
and
Security Administration
domains in the Organizations and Roles functional area.
The report is available on mobile but we recommend that you view it on desktop.
You can use this report to view role-based security access for workers, constrained security groups and role assigners, and identify when a worker has had their role-based security access granted, revoked or had no security impact, and for what reason. You can use it to identify when the staffing transaction has been rescinded or corrected, and for what reason. You can also use the report to view security changes between role assignments and the role assignee.
  1. Access the
    Role-Based Security Audit Report
    .
  2. From the prompt, fill out the relevant fields. The
    Effective Moment From
    and
    Effective Moment To
    fields are required and show one month of entries, prior to the current date, by default.
  3. (Optional) Check the
    Include Transactions with no Assignable Role
    box. Checking the box ensures that If you hire a worker into an unfilled position with no role assignments, then this transaction only appears in the report if the box is checked because there was no role assigned to the position at the time of hire.
    • The report doesn't return entries that don't impact role-based security.
    • There are no restrictions on the combinations of
      Role Assigner
      and
      Assignable Role
      values that can be selected.
    • If you change the name of security group, the name updates automatically and a new entry isn't logged in the report for this change.
    • Entries display for staffing transactions linked to unconstrained security groups but the report won't display direct changes to unconstrained security groups.
    • The report logs entries for workers in positions and position restrictions.
  4. The report displays a table of audit entries. Consider these columns:
    Security Effective as of
    Logs the moment the security came into effect.
    Security Change Reason
    The reason for the security change. If you make a security change using mass actions, this column will be empty.
    Security Change Reason Details
    Gives a more detailed description of the security change.
    • If you use the
      Swap Positions
      task to change a job, the
      Security Change Reason Details
      of the entry will display as
      Change Job
      .
    • If you use the
      Swap Positions
      task to rescind a job change, the
      Security Change Reason Details
      of the entry will display as
      Swap Positions
      .
    Security Outcome
    Displays the outcome of the security change.
    • A
      Security Granted
      entry is always logged when a new hire is created to provide a complete staffing audit trail. If the hire isn't assigned to a role-based security group during the hire, these entries display no security impact.
    • For every future role assignment snapshot that a worker is on, there is an entry logged as
      Security Granted
      . We recommend reviewing the security change reason details column in these scenarios.
    • When a
      Security Change Reason Detail
      impacts a role-based constrained security group,
      Potential Impact
      displays.
    Role Assignee
    • If there's no job title, the column displays the job posting.
    • If there's a future-dated hire, the job title displays the job posting title until the hire becomes effective.
    • Once a worker is terminated, all past entries revert to the job posting title.
    • For changes to security groups, the
      Role Assignee
      and
      Worker
      fields are empty.
    Transaction
    Details the staffing event. If the entry doesn't have a business process, the field will be empty.
    If you make a security change using mass actions, this column will be empty.
    Security administrators with access to the
    View All
    action on the business process policy of the staffing event, can click into the link in this column in the report and view if the roles have been assigned or revoked using an EIB.
You have a detailed report that you can use to improve how you audit role-based security.
Dylan Johnson has changed role and his security access is updated. I want to use the report to view the details for the change. I filter by name on the
Worker
column. I can see two
Change Job
audit entries for Dylan:
  • The first entry shows me a
    Security Change Reason
    of
    Job Change Vacate
    , with
    Security Change Reason Details
    of
    Change Job
    and
    Security Outcome
    of
    Security Revoked
    .
  • The second entry for Dylan shows me a
    Security Change Reason
    of
    Job Change Fill
    , with
    Security Change Reason Details
    of
    Change Job
    and
    Security Outcome
    of
    Security Granted
    .
I can see that Dylan’s role has changed. His first entry shows him as a manager and the second shows him as a senior manager. His security group access has also changed on the second entry. I can see by these audit entries that Dylan has changed job from a manager to a senior manager role.