Set Up Segmented Security by Compensation Plans
- Analyze your organization's needs and decide whether segmented security for compensation is appropriate. Evaluate your current organizational structure and thoroughly understand segmented security requirements.
- Configure organizational hierarchies, security groups, and organizational roles.The use of segmented security groups won't apply to every business; it involves a number of complex steps and impacts your overall compensation practice. Even if you currently use location hierarchies for other purposes, your current hierarchies might not be adequate for restricting access to compensation components. Also, intersection security, constrained job-based security groups, and rule-based security groups aren't supported for Compensation.
- Create location hierarchy organizations that parallel the segments you need.
- Security:
- Set Up: Compensation Security Segmentsdomain in the System functional area.
- Set Up: Tenant Setup - HCMdomain in the System functional area.
- Set Up: Assignable Rolesdomain in the Organization and Roles functional area.
- Reports: Organizationdomain in the Organization and Roles functional area.
- Security Configurationdomain in the System functional area.
- Worker Data: Non-Funded Plan Assignmentsin the Core Compensation functional area.
- Self-Service: Non-Funded Plan Assignmentsin the Core Compensation functional area.
Segmented security groups divide access to Compensation setup data (such as Compensation Plans) among multiple Compensation Partners. Example: A business with sites in Canada, the U.S., and Mexico might require a separate Compensation Partner for each country with appropriate access to the setup data.
Compensation Administrators need access to all compensation segments you create, no matter how you decide to segment your organization's compensation groups.
- Enable the segmented security group feature for compensation.
- Access theEdit Tenant Setup - HCMtask.
- In theCompensationsection, select theEnable Compensation Setup Segment Securitycheck box.
- Enable theCompensation Partnerrole for theLocation Hierarchyorganization type.
- Access theMaintain Assignable Rolestask.
- In theEnable for Organization Typescolumn, addLocation Hierarchyto any organization types already enabled.
- In the applicable location hierarchy organization, assign theCompensation Partnerrole to the desired worker.
- Access theView Organizationtask.
- Open the applicable location hierarchy organization.
- From the related actions menu, select .
- In theAssign Rolessection, selectCompensation Partneras theRole, and select the desiredWorkerto whom theRoleshould be assigned.
- Create an organization membership security group that includes the applicable location hierarchy.
- Access theCreate Security Grouptask.
- ForType of Group, selectOrganization Membership Security Group.
- In the list ofOrganizations, add the desired location hierarchy to the security group.
- Specify whether the new organization membership security groupApplies to Current Organization OnlyorApplies to Current Organization And All Subordinates.
- Create an intersection security group that includes the applicable organization membership security group and the Compensation Partner security group.
- Access theCreate Security Grouptask.
- ForType of Group, selectIntersection Security Group.
- In the list ofSecurity Groups, add the desired organization membership security group and the Compensation Partner security group.
- Create a security segment for the desired compensation component, such as country.
- Access theCreate Compensation Setup Security Segmenttask.
- Select thePay Component(or set of components) to contain within the segment.
- Create a segment-based security group that joins the applicable intersection security group with the applicable security segment. This is a critical step that ties together the preceding steps.
- Access theCreate Security Grouptask.
- ForType of Group, selectSegment-Based Security Group.
- In the list ofSecurity Groups, add the applicable intersection security group.
- In the list ofAccess Rights, add the applicable security segments.
- Repeat steps 3 through 7 for each secured compensation segment you want to create.
- Create a segment-based security group for the Compensation Administrator that joins the Compensation Administrator with all the security segments created.
- To use any new segment-based security group that you've created, update and activate the domain security policy and business process security policy for the Compensation functional area.
- Access theFunctional Areasreport.
- From the related actions menu for Core Compensation and Advanced Compensation, select (orView Domain Policies).
- ClickEdit Permissions.
- Add the segment-based security group to the applicable domain security policy/business process security policy.
- Delete theCompensation Partnersecurity group from the applicable domain security policy/business process security policy.
- Access theActivate Pending Security Policy Changestask to confirm changes.
You can use the
All Compensation Setup Security Segments
report to review which intersection groups constrain the segment-based security groups for a particular compensation segment or component.