How Do I Setup a User Profile, Company and OrgUnit Permissions for a New User Or Edit An Existing User? Article

How Do I Setup a User Profile, Company and OrgUnit Permissions for a New User Or Edit An Existing User? Article

Once a User has been created (please see How Do I Create New User/s Using the Windows Corporate Directory? or How Do I Create A New User Using Dynamic Budget's Security? for more information), the next steps are to assign them with Profile elements, and Company and OrgUnit Permissions.


In this article the following is discussed:

i. Setup Role

ii. Setup Feature Access

iii. Setup Admin Menu Access

iv. Searching for and Granting Access to OrgUnits

v. Grant Access to All Searched for OrgUnits

h. "Read" Permissions

I. "Write" Permissions

J. "Approve" Permissions

K. and L. "Sensitive Summary" and "Sensitive Detail"

M. "Sensitive Level"

N. Account Level Security

3.b. "Synch OrgUnit Permissions"


4. Data Security Hierarchy



Please note that for Window Corporate Directory Users only step 1 and 3 (a or b) are required as step 2 has been completed on Map Users to Companies.


1. The User's Role, Feature Access and Admin Menu Access needs to be completed on Assign User Permissions/User Profile tab.


i. Setup Role

The default role when setting up a new User is the Application User role. From the drop down menu there are five roles to select from:

Please see What Can the Different Roles Do To Set Security and What Menus Can Each Role See? and AutoSynch and Synch OrgUnit Permissions to determine what Role is most suitable for your user.


Once the Role is selected click

.


ii.Setup Feature Access

Checking the box for "Manage Capex" and "Edit ST/OT" Hours provides the User with access to those menu items in the Budgets menu as below.

Please see Edit ST/OT Hours and Manage Capex for information about these menu items.


Checking the "Project Tracking" box provides Users with access to the below menu items in the Allocations menu .  However, please note that as below the "Allocations" item needs to checked on Admin Access Menu in order for the User to have access to the "Project Budget Tracking" menu item.  Also, as Application Users cannot be given access to Admin Access Menu items, they will not be able to view and use this feature.

The Project Variance and Project Budgets Reports are visible provided the "Allocations" item is checked.


 
As discussed above the below Allocations checkbox needs to be checked for Users to view the "Project Budget Tracking" menu item.

 When selections are completed please click


.


iii. Setup Admin Menu Access


All Roles except Application User can be provided access to the Admin Menus. "Administrator- Restricted" Users can neither assign Payroll menus to themselves nor other Users.

To provide access check the appropriate box.


By Checking Tools, System Management, Allocations and User Management the following menus are available to user as are their menu items.  (The exception are some items under Allocations for Project Management.  Please see ii. above)



For information on he Payroll checkboxes and related menu access, please see How Does Payroll Security Work?


When selections are complete please click

.



2. Permissions to access CompanyDB and Autosynch rights are set on Assign User Right/Company Permissions tab.


Print, Export to Excel, Print to PDF, Auto-size Columns, Filter, Expand/Reduce Column Width and Copy and Paste, Select All/Deselect All standard functionality is available.


The following Right-Click Menu and Short-Cut Keys are available:




A To give the user access to a company check the "ACCESS" box.  Please note the name of the CompanyDB is listed in the CompanyDB column;

B. To give a user access to the "AUTOSYNC" function for the CompanyDB check this box. Please see AutoSynch and Synch OrgUnit Permissions for a full explanation of this functionality.


The "ACCESS" box needs to be checked in order for the "AUTOSYNC" functionality to be turned on for a CompanyDB.


C. To save selections click "Save User Companies".


The Company Tag1 - 5 that are highlighted in yellow are defined on the Bulk Company Management.  Please contact Dynamic Budgets before making any changes to these sensitive fields.




3.A. Customizing Access to OrgUnits, Sensitive Levels, Sensitive and Accounts (if Necessary) for Users.


Filter and Select/Deselect All functionality is available.


The following Right-Click Menu and Short-Cut Keys are available:



iv. Searching for and Granting Access to OrgUnits



A. Select from the drop down menus the CompanyDB, OrgRollup and OrgUnit you wish to review.  By drilling down on the highlighted OrgUnit the OrgTag1-10 are available as  search fields.  (The OrgTags and OrgRollup are user-defined on the Manage OrgUnits.)


B. By selecting from the drop down Company Tags  1-5 can either be displayed or hidden from the search results;
C. By selecting from the drop down OrgTags 1- 10 can either be displayed or hidden from the search results;
D. Click "Search OrgUnits" to display the result of the search criteria.

Below is a search result with the Comp and Org Tags displayed:


E. To grant the user access to specific OrgUnit/s, select the required OrgUnit/s; then
F. Click the "Grant Access to Selected" button.


The result is that the selected OrgUnits will now appear in the Users Permissions as illustrated below.  Please note that the default access is to "Read".  The Users will now be able to read (view) the OrgUnit data.  However additional security can be turned on at the Object and Account levels which prevent viewing of the secured data until the User is given appropriate security.  Please see K-N below for more information.


Please click

 to save your work.



v. Grant Access to All Searched for OrgUnits
G.  First search for the OrgUnits you wish to grant access to and then click the "Grant Access to All" button.  Then click

 to save your work.



Below illustrates the granting of all OrgUnit access to the User:




h. When a User is granted permissions to a new OrgUnit  "Read" access is the default.  "Read" access permits the User to only view the data.  However additional security can be turned on at the Object and Account levels which prevent viewing of the secured data until the User is given appropriate security. Please see K-N below for more information.  To remove "Read" permissions uncheck the box for the required OrgUnit and then "Save User". 
I.  In order for the User to change data, "Write" permissions need to be assigned.  To do so, check the box for the required OrgUnit and then "Save User".  To remove "Write" permissions uncheck the box for the required OrgUnit and then "Save User".

Also the "Write" settings permits the User to Lock Budget Account on submission (Edit Status and Account Approval), if this functionality is enabled on App Config/Menu Editor



J. In order for a User to be able approve Budget Accounts, this checkbox needs to be checked for the required OrgUnit/s.  To remove "Approve" permissions uncheck the box and "Save User".  Please see the Edit Status and Account Approval article for more information on how to approve Budget Accounts.  Also, this functionality needs to be turned on App Config/Menu Editor, and can include Locking/Unlocking Accounts functionality:





K.  and L.  To provide Users with the ability to view a Budget Account Number that has been setup as "Sensitive" check the " Sensitive Summary" box for summary information and/or "Sensitive Detail" box for detailed information and then click

.


L.  To provide Users with the ability to view an Object that has been setup with a "Sensitive Level" from the drop down menu select the appropriate Sensitive Level and then click

.


M.  Account level security is both turned on and assigned at the Budget Account level.  This is in comparison to "Sensitive Level" which is turn on at the Object level and "Sensitive" which is turned on at the Budget Account level but both "Sensitive Level" and "Sensitive" are assigned at the OrgUnit level.  If Account Level Security is turn on Accounts permission to view the Account needs to be completed. Please see How Do I Activate and Use Account Level Security? for more information


3.b. "Synch OrgUnit Permissions" can be used to assign standard security settings to Users based on their Role instead of manually assigning Users permissions as per 3.a. above.  Please see AutoSynch and Synch OrgUnit Permissions for more information.  And then if necessary, Users settings can be customized as per 3.a. above after assigning standard security settings to them.


4. Data Security Hierarchy

As discussed above access to data can be secured at different levels.  And depending on which security features are turned on users will need to be assigned the appropriate security to view the data,  The data security hierarchy is as follows:



    • Related Articles

    • AutoSynch and Synch OrgUnit Permissions Article

      When new Account Numbers are setup in Great Plains Accounts ("ERP") software it is necessary to maintain a mirror image of those Account Numbers in Dynamic Budgets.  This process is managed through the Synchronize Chart of Accounts and its related ...
    • Assign User Permissions Article

      PDF Tutorials  Interactive Tutorial Cropped Screenshots Full Page Screenshots           Step By Step Tutorial - Assign User Permissions CLICK ON THE BLUE LINK ABOVE TO VIEW TUTORIAL See attached PDF's, and Other Tutorials & Knowledge Base Page Links ...
    • User Profile Article

      The user profile window has three (3) tabs:  1. User Info 2. System Info 3. Error Reporting User Info Tab To change password, enter existing password, a new password, and enter the password a second time to confirm. Enter the User's First & Last Name ...
    • Edit Status, and Account Approval Article

      Several screens include the ability to notate rows with an Edit Status and/or Account Approval.  1) Select the row to notate with the Edit Status and/or Account Approval; 2) Then use the pulldown menu for either Edit Status or Account Approval and ...
    • How Do I Clone/Duplicate an Existing User's Profile, Company and OrgUnit Permissions to a New User? Article

      The clone/duplication feature is found on the Assign User Permissions/User Profile tab.   ​ 1. Highlight the User you wish to clone/duplicate by clicking anywhere in the row .  Their User Profile will appear to the right; 2. Enter the new User ID ...