Set Up Role-Based Security Reporting
Security:
Customer Central Security Administration
and Security Administration
domains in the Organizations and Roles functional area.The report is available on mobile but we recommend that you view it on desktop.
You can use this report to view role-based security access for workers, constrained security groups and role assigners, and identify when a worker has had their role-based security access granted, revoked or had no security impact, and for what reason. You can use it to identify when the staffing transaction has been rescinded or corrected, and for what reason. You can also use the report to view security changes between role assignments and the role assignee.
- Access theRole-Based Security Audit Report.
- From the prompt, fill out the relevant fields. TheEffective Moment FromandEffective Moment Tofields are required and show one month of entries, prior to the current date, by default.
- (Optional) Check theInclude Transactions with no Assignable Rolebox. Checking the box ensures that If you hire a worker into an unfilled position with no role assignments, then this transaction only appears in the report if the box is checked because there was no role assigned to the position at the time of hire.
- The report doesn't return entries that don't impact role-based security.
- There are no restrictions on the combinations ofRole AssignerandAssignable Rolevalues that can be selected.
- If you change the name of security group, the name updates automatically and a new entry isn't logged in the report for this change.
- Entries display for staffing transactions linked to unconstrained security groups but the report won't display direct changes to unconstrained security groups.
- The report logs entries for workers in positions and position restrictions.
- The report displays a table of audit entries. Consider these columns:Security Effective as ofLogs the moment the security came into effect.Security Change ReasonThe reason for the security change. If you make a security change using mass actions, this column will be empty.Security Change Reason DetailsGives a more detailed description of the security change.
- If you use theSwap Positionstask to change a job, theSecurity Change Reason Detailsof the entry will display asChange Job.
- If you use theSwap Positionstask to rescind a job change, theSecurity Change Reason Detailsof the entry will display asSwap Positions.
Security OutcomeDisplays the outcome of the security change.- ASecurity Grantedentry is always logged when a new hire is created to provide a complete staffing audit trail. If the hire isn't assigned to a role-based security group during the hire, these entries display no security impact.
- For every future role assignment snapshot that a worker is on, there is an entry logged asSecurity Granted. We recommend reviewing the security change reason details column in these scenarios.
- When aSecurity Change Reason Detailimpacts a role-based constrained security group,Potential Impactdisplays.
Role Assignee- If there's no job title, the column displays the job posting.
- If there's a future-dated hire, the job title displays the job posting title until the hire becomes effective.
- Once a worker is terminated, all past entries revert to the job posting title.
- For changes to security groups, theRole AssigneeandWorkerfields are empty.
TransactionDetails the staffing event. If the entry doesn't have a business process, the field will be empty.If you make a security change using mass actions, this column will be empty.Security administrators with access to theView Allaction on the business process policy of the staffing event, can click into the link in this column in the report and view if the roles have been assigned or revoked using an EIB.
You have a detailed report that you can use to improve how you audit role-based security.
Dylan Johnson has changed role and his security access is updated. I want to use the report to view the details for the change. I filter by name on the
Worker
column. I can see two Change Job
audit entries for Dylan:
- The first entry shows me aSecurity Change ReasonofJob Change Vacate, withSecurity Change Reason DetailsofChange JobandSecurity OutcomeofSecurity Revoked.
- The second entry for Dylan shows me aSecurity Change ReasonofJob Change Fill, withSecurity Change Reason DetailsofChange JobandSecurity OutcomeofSecurity Granted.