Edit Prism Data Source Security
- Security:Prism: Manage Data Sourcedomain in the Prism Analytics functional area.
Before you make Prism data in a table or dataset available for analysis, configure the security (security domains and securing entities) that Workday applies to the data in the Prism data source. You configure the data source security by editing the table or dataset, but Workday applies the security to the data in the Prism data source.
The configured securing entities work with the configured security domains and their security groups to determine which users have access to which rows, fields, and field values in a Prism data source.
A securing entity is an Instance or Multi-Instance field that you use to constrain access to particular instance values for reporting and analytics. A securing entity:
- Is typically a role-enabled Instance field, such as Cost Center or Supervisory Organization.
- Is the Person Instance field (secured to thePerson Data: Person Reportsdomain) for self-service security groups.
- Determines which instance values Workday displays to a user based on the role assigned to the user.
Use securing entities to control row-level and field value-level access in a Prism data source for users in constrained security groups.
For a user to have access to a particular row or field value in a Prism data source, they must be a member of 1 of these security groups:
- An unconstrained security group that has permissions on a domain configured in the data source security.
- A constrained security group that has permissions on a domain configured in the data source security, and the corresponding securing entity is configured.
Workday restricts user access to data in a Prism data source for these security groups:
- All unconstrained
- Role-based constrained
- Aggregation when role-based
- Intersection when role-based
Workday has tested and supports using securing entity fields that use these business objects:
- Company
- Company Hierarchy
- Cost Center
- Cost Center Hierarchy
- Person
- Location Hierarchy
- Region
- Region Hierarchy
- Supervisory Organization
When no data source security is configured for the Prism data source, Workday applies the
Prism: Default to Dataset Access
security domain. The Prism: Default to Dataset Access
domain provides contextual access to a Prism data source based on your access to the underlying table or dataset.You can’t explicitly configure the
Prism: Default to Dataset Access
security domain when you define data source security. When you access the View Data Source Security
or Edit Table
tasks and they indicate that the Prism: Default to Dataset Access
security domain has been configured, that means that no domain has been configured explicitly. To view the domain that’s currently applied to a Prism data source, access the View Prism Data Source
report.- Access theEdit Data Source Securitytask for the table or dataset you want to apply security to.
- In theDomainsprompt, select 1 or more security domains to use to determine who can see the Prism data source.If you specify a security domain that has a constrained security group, then you must specify an appropriate securing entity.
- (Optional) In theSecuring Entitiesprompt, select 1 or more fields in the dataset. Workday lists the Instance or Multi-Instance fields in the table or dataset that act as securing entities.The securing entities work with the:
- Data Source Securitydomains to determine row-level access for a user.
- Field Level Securitydomains to determine field value-level access for a user.
Workday uses any in common logic when evaluating the contextual security using a Multi-Instance field.When you specify more than 1 securing entity that relates to the same security group, Workday uses the OR condition between them. Depending on how your security groups are set up, a user might see some additional rows or field values. Make sure you test the report results to ensure that the report produces expected results for each user. - In theDefault Domain(s) for Dataset Fieldsprompt, select 1 or more security domains that Workday applies to every field in the Prism data source unless you override the domain for a particular field in the next section.When you add new fields to the table or dataset, Workday applies this default domain to the new fields. You might want to consider specifying a domain with more restrictive access. Then you can override the default domain on a per field basis to allow more access as necessary.
- (Optional) You can select different domains to apply to specific fields to override the default domains.
- Review anySecurity Configuration Auditmessages to learn more about any issues with the configured securing entities and domains.
- (Optional) ClickBackto make any changes to the configured security options based on the audit messages.
- Select theApply Securitycheck box to apply your changes.If you want to restrict access to rows using any of these security group types, Workday can't honor those restrictions:
- Segment-based security groups
- Job-based security groups
- Manager's Manager security group
- (Required for datasets) Publish the dataset again to apply the new security configuration to the Prism data source.
Workday saves the security information. You can view the current security status by selecting .
Suppose that you select these domains containing these security groups. To enforce contextual security at the row-level and field value-level, then use these fields as securing entities:
Security Domain | Contains This Security Group | Use This Securing Entity |
|---|---|---|
Custom Domain 28 | HR Partner (By Location) | Location |
Custom Domain 29 | Manager | Supervisory Organization |
Custom Domain 30 | HR Administrator | None required.
HR Administrator is an unconstrained security group, so it doesn't require a securing entity. |
Public Reporting Items | None. | None required.
This domain provides access to all publicly available fields and Workday-delivered data sources. |
Create the Prism data source by enabling the table for analysis or publishing the dataset. Workday applies the security restrictions to the data in the Prism data source.