Levels
The Levels feature (part of Segregation of Duties) lets you control user access down to an individual record level.
The level is a numeric value between 1 and 9999. 1 is the highest level of access. This provides flexibility for even the most complex administrative requirements.
Levels are controlled by settings within Security Profiles and within individual records.
Users are given levels by the profile they are assigned to.
Records can be left at the default level of 0 (no level control) or given a level greater than 0, which restricts usage to users with specific levels.
If a record has level 0, all users can view, edit, and delete it, subject to module access permissions.
Each time a user with a level tries to access a record with a level, the system compares the two levels to determine access.
The Next and Previous buttons on the record window are disabled to prevent the user from moving to records they cannot access.
You can view and amend an individual record's level via the Info button on the main record window.
Administering levels on a record-by-record basis is impractical, so levels are specified within Security Profiles. Within a Security Profile, you specify two default levels: the Enter/Amend Level, which is assigned to all records entered by users with this profile; and the Work With Level, which is checked when those users process transactions.
Both levels apply to records.
The Work With level must be higher in seniority than the Enter/Amend level.
If you try to set a Work With level that is lower in seniority than the Enter/Amend level, the system shows a warning and does not allow you to continue.
Only the Work With level applies to transactions.
For example, you might assign level 1 to company directors and the system administrator, giving them access to all records. Then assign level 10 to the next most senior team members, increasing the level by increments of 10 as users become more junior.
Users can Enter/Amend or Work With all records at the level specified in their Security Profile, and all records with a numerically greater level.
There is also an Exact option, which limits users to records that exactly match their level. If this is set, the Enter/Amend and Work With levels must be identical.
Other considerations
What happens when, for example, a Customer’s default Analysis Code carries a Level numerically less than that of the User entering a sales transaction?
E.g. Customer 20, Sales Analysis 10, User’s Work with 20.
This presents the situation whereby the User is authorised to work with the Customer record, but not with the Analysis record. In this situation, the system retains the default Analysis Code but, if the user attempts to specify a different Analysis Code, the system will only allow them to use an Analysis Code with a Level at or numerically greater than their own (or at their own Level only if the Exact option has been selected).
Set up levels
Levels are not required — all records default to level 0, allowing full access to all users with appropriate module permissions. If levels are used, only the system administrator and directors should have Enter/Amend level 1, giving them full access to all records. Level 0 then becomes a global level where everyone can see those records. Assign level 10 to the next most senior staff, then increase in increments of 10 as users become more junior. To set up a Security Profile with levels:
Click Security Profiles. The Security Profiles window opens.
Click the Maximise button to ensure the full window is visible.
Browse to an existing profile and click Duplicate to copy its settings to a new profile, or:
Click Insert.
Enter a code and description for the new profile.
Click Level Defaults.
Enter the appropriate levels in the Enter/Amend (Records) and Work With (Transactions) fields.
Set the default levels to Apply to all Modules, or manually select the modules you want the levels to apply to.
If levels are already set within the security profile, these settings will overwrite any existing settings on the selected modules.
You can set levels to Exact — this limits the user to only records that exactly match the specified level.
These settings apply to all records in the selected modules and override any individual record settings. You can then alter individual records as needed.
Click OK to save and apply the levels to the selected modules.
Set the Default Options at the top of the Security Profiles window to Full, View, or No Access.
Set Default Menu items to Enabled or Disabled as required.
In the Menu and Options area, set the rights for each module and its functions.
Clicking a module in the menu list (such as Sales Ledger) shows the functions within it.
Clicking a function shows the sub-functions within it.
Clicking a sub-function lists the individual items that can be controlled.
When working with records, the current levels assigned to them are shown. Additional fields appear at the bottom of the window so you can set Enter/Amend and Work With levels (and Exact if required) on a record-by-record basis.
Click OK to save.
You can insert a profile and adjust defaults later. Once a user is assigned to a profile, logging in as that user applies the settings currently configured for that profile.
Set up record levels
Each record within the system can have Level attributes.
The level information appears in the window shown by the Info button on the record screen.
If not specifically entered, levels default to the user's Enter Level from their profile.
The user can enter any value equal to their level or numerically greater. If Exact is set, they can only enter a value exactly equal to their level.
If a record has level 0, all users can access it with no level control.
📌 Note: Only a user with no levels set can insert a record with level 0. If this is needed, create a special profile with the levels left blank. These level attributes are applied whenever a user tries to view, edit, or process transactions involving that record.
Transaction processing
Entering transactions requires the user to have Work With rights on the relevant records — for example, to raise a Sales Order for a stock item, you need rights for Customer records, Stock records, and Sales Analysis records. For processing transactions from the batch, you need rights to the primary record.
Examples:
Customer permissions for updating Sales Orders and Receipts.
Supplier permissions for updating Purchase Orders and Payments.
Nominal Records permissions for updating Journals.
Projects permissions for updating Timesheets.
Processing from Batch specifically does not segregate by say Resource, Sales Analysis or Purchase Analysis.
Stock Takes and Sub Analysis Transfer will also apply for the User’s Work With list for the main Stock Record but will also only show Sub Analysis records which the User has permission to work with via their Security Level.
Assembly Stock records and all the included Component records must be within a User’s Stock Record Work With list.
Special notes about Defaults
The system has ‘default’ settings for Bank, Sales, Purchase and Discount Analysis. These may be currency or Stock Record dependent.
The ruling for how these work with Levels is:
The system delivered defaults (i.e. where entered by the system and NOT typed in by the user or selected from a tab-off list) fall OUTSIDE the Levels control.’
An example of how this may affect a user is as follows:
The customer record is set up without a specific bank default analysis.
The default Bank Analysis record has no level set, as the accountant chose not to apply one.
On the detail line of a transaction, the admin user requires a Sales Bank Analysis. The system delivers the default.
At this point, the user can accept the default by pressing Tab, in which case level verification is not performed. If the user types a code or tabs off to select one (even the same default), levels apply and entry may not be permitted to that account.
In this example, if it were thought to be a problem, a second Bank Sales Analysis could be set up in a different setting.
If a record’s Code is entered on another record as a default setting, e.g. Sales Analysis on the Stock Selling Price table, then it is assumed to have a Level of 0 (i.e. can be seen by all Users).
However when processing a Transaction using, for example, a Stock record, if the Analysis Code (correctly entered by the system as the default to use), is then changed, altered, edited, deleted etc., in any way, the subsequent popup for the Analysis Code will be the User’s restricted list.
The system delivered defaults include all types of defaults where the system is recommending the Analysis code – this may be coming from the Customer Record, the System Control, the currency record, the Stock Record etc.
Default levels
📌 Note: This feature is not available in Dimensions Lite. When setting up a Security Profile, set up the default levels first.
Click Level Defaults. The default levels window opens.
Enter the appropriate levels in the Enter/Amend (Records) and Work With (Transactions) fields.
A level of 0 means no level control. Users on this profile can view, edit, and delete any record, subject to module access permissions.
Enter a level greater than 0 to restrict users to records with specific levels. The system compares the user's profile level to the record level each time access is attempted.
Set the default levels to Apply to all Modules, or select individual modules.
If levels are already set within the profile, these settings will overwrite existing settings on the selected modules.
You can set levels to Exact — this limits users to records that exactly match their level.
These settings are applied to the selected modules, overriding any individual settings. You can then adjust individual records as needed.
Click OK to save and apply the levels to the selected modules.
Additional notes
When you first open a Security Profile, all fields and windows are blank.
Selecting an existing profile and clicking Edit shows which modules are available (green tick) or unavailable (red cross).
Inserting a new profile without setting defaults results in all menus, sub-menus, and options being disabled. All modules are shown in a tree structure.
Clicking the text next to the tick or cross expands the options.
Following assignment of a User to the Profile, that User’s options would be applicable the next time they logged onto Accounts.
