Security Profiles
Dimensions Only - This feature is not available in Dimensions Lite
Security Profiles are used to control User access to every function within the system. Each User record must be assigned to a profile and you can create as many profiles as you need. There are a number of profiles which are automatically created by default, these are to provide you with a starting point for creating role-based Security Profiles. See the Default Security Profiles section, below.
You must be connected as a User with the correct privileges to insert/ edit Security Profiles. From the Profile ribbon, use the Insert function to insert a profile, or the Browse or Find buttons to locate an existing profile.
Contents |
When changes are made to the security profile that is being used by the User who makes the changes, these changes will only come into effect after the Reset User Transaction Options has been applied.
Code
Enter a unique Code for the new Profile record; alternatively, use the Find, Previous, and/or Next ribbon buttons to locate an existing code.
Description
A meaningful description for the associated Code.
Default Menu Items To
Select from Enabled or Disabled. If you select to default the menu items to Disabled, all the menu items will be disabled and you must manually enable the menu items that are to be permitted for this profile; alternatively, if you select to default the menu items to Enabled, all the menu items will be enabled and you must manually disable the menu items to which Users with this profile are not to be given access.
Menu
The individual entries at each level have a tick to indicate that they are enabled, or a cross to indicate that they are disabled. Clicking on a check or an 'X' switches to the opposite sign. Clicking on an enabled entry at any level will highlight the entry and expand the list to show the entries within that level, and, in the right-hand pane, the security options for that level.
Levels
The Levels feature is a part of Segregation of Duties and allows you to assign User access down to individual record level. E denotes Edit permissions, whereas W denotes Work with permissions. You are also able to set Exact permission, e.g work with only level 12. In the main Menu pane, these are read-only. These properties are set in the footer of the Options pane.
Default Options To
This drop-down defaults the security options, for the highlighted Menu entry, to the choice you select. Select from No Access (Access is denied), View Access (User is given read-only access), or Full Access (User is given full read/write access). Also, see Transaction Options Defaults section, below.
Note that there are two types of Options listed: 'actions' (e.g. Edit, Delete) and 'window access' (e.g. EC Info). When selecting View Access, only options relating to window access are set (e.g. it would not make sense to give View access to a Edit action)'. 'Window access' can be No Access, View Access, or Full Access, whereas 'actions' must be Enabled or Disabled.
If you want to give mixed access, you should first Default Options To give Full Access or No Access and then manually amend the required actions.
Options
The security status for each Option is displayed. To change the security status for an option, click on the current status to display the menu of alternatives and then select the status you require.
Levels properties are set in the footer of this pane.
Ribbon tasks
The majority of these tasks are described fully elsewhere in this help.
Functions specific to Profiles are:
Export/ Export All/ Import
Global
Budgets
Periods
Levels
Hide Fields
Reset
Users
Corrections
Sub Analysis
Default Security Profiles
The following profiles are created automatically when creating a new database. These are meant to provide you with a starting point for creating role-based Security Profiles.
| Details |
Code | MASTER |
Description | Master |
Module Access | Access enabled for all modules and sub features |
Enquiry Access | Access enabled for all Enquiry lists |
Rules | Edit and Delete functionality is not available. This profile is used as the default for new User records if the USER profile has been deleted. |
|
|
Code | USER |
Description | User |
Module Access | Access enabled for all module and sub features. |
Enquiry Access | Access enabled for all Enquiry lists. |
Rules | Edit and Delete functionality is available. This profile is used as the default for new user records unless it has been deleted, in which case the MASTER profile is used. |
|
|
Code | CRM USER |
Description | CRM User - to be used with CRM-only unlock |
Module Access | Access enabled for CRM and all sub features of CRM. Access enabled for Sales Orders > Transactions > Orders and Estimate. |
Enquiry Access | Access disabled for all Enquiry lists |
Rules | Edit and Delete functionality is available. You may deny access to the modules listed, but not enable access to any other modules within this profile. This profile is the default for new user records where a CRM-only unlock has been applied. |
|
|
Code | CRC USER |
Description | Credit Control User Only |
Module Access |
Access enabled for:
|
Enquiry Access |
Access is enabled for the following Enquiry lists:
|
Rules | Edit and Delete functionality is available. |
|
|
Code | SALES |
Description | Sales User Only |
Module Access |
Access enabled for:
|
Enquiry Access |
Access enabled for the following Enquiry Lists:
|
Rules | Edit and Delete functionality is available. |
|
|
Code | PURCHASING |
Description | Purchasing User Only |
Module Access |
Access enabled for:
|
Enquiry Access |
Access enabled for the following Enquiry lists:
|
Rules | Edit and Delete functionality is available. |
|
|
Code | STOCK |
Description | Stock User Only |
Module Access | Access enabled for Stock Control and all sub features of Stock Control. |
Enquiry Access |
Access enabled for the following Enquiry lists:
|
Rules | Edit and Delete functionality is available. |
|
|
Code | FINANCE |
Description | Finance User Only |
Module Access |
Access enabled for:
|
Enquiry Access |
Access enabled for the following Enquiry lists:
|
Rules | Edit and Delete functionality is available. |
|
|
Code | PROJECTS |
Description | Projects User Only |
Module Access |
Access enabled for:
|
Enquiry Access |
Access enabled for the following Enquiry lists:
|
Rules | Edit and Delete functionality is available. |
Transaction Options Defaults
When Transaction type menu items are selected, e.g. Invoices, a column of tick-boxes will be displayed to the right of the Enabled/Disabled menus, below the heading Default.
These are the User Transaction Options that are available for the transaction from the options icon on the input window.
You should select the defaults that you wish Users with this profile to use. The option can then be disabled so that the Users cannot change them.
For example, if Users with this profile are expected to batch invoice transactions then the Batch Transaction default should be ticked. If they must always batch invoice transactions, tick the default and disable the option so that it cannot be changed by the User.
Alternatively, if the user can make the choice, tick the default but leave the option enabled (see Bypass costing on the detail window).
If you change any of the defaults, you must press Reset User Transaction Options on the tool bar after saving the Profile.
Other Transaction Options
In Orders options, the Ignore Credit Card Details option can be set if a User is not required to enter credit card details for mail orders in SOP. In this case, the Credit Card menu will be set to Ignore.
Access to the tab cards on the right of the transaction entry windows is controlled by settings in the User Profile, e.g. Invoices where the last two options, Account Notes and Aged Debtors, are the tab cards on the transaction entry window.
Multi Currency Price Records
On the Security profiles for the Price Record in SOP, POP and PIR there are two options required on the record - Sell Price and Cost price. For each you can select access permissions of:
Full Access - you are able to use the drill-down to the price tables, and edit.
View - you are able to use the drill-down to the price tables, but not edit.
No access - the drill-down to the price tables is disabled.
Price Change Control
You are able to control whether a User can change the Price on an Order by editing the Price field or by using the Price search window.
You can also prevent a User from viewing the Prices in the search window, and from looking at the Prices on the Sub Analysis record.
Within Security Profiles:
View/ Edit Prices
The View/ Edit Prices option is in:
Orders
Credit Notes
If the option is set to Enabled then the User can operate as usual. If the option is set to Disabled then:
The User cannot edit the Price (home or currency) on the detail window.
They cannot look at the Price list window.
On the Stock search window they cannot view the Cost Prices, even if detailed search is chosen.
On the Sub Analysis drill down, the Analysis, Valuation and Landed Cost tab cards are disabled.
Edit Buying Prices
Orders
Credit Notes
Request to Purchase
If the option is set to Enabled then the User can operate as usual. If the option is set to Disabled then:
The Edit Buying Prices option will be in:The User cannot edit the Price (home or currency) on the detail window.
They cannot look at the Price list window.
On the Stock search window the user cannot view the Sales Prices, even if detailed search is chosen.
Email and XML
The security options for Email and XML output will default to:
Allow Email facility - Enabled
Deny XML facility - Enabled
This means that Email facilities are enabled and XML facilities are disabled.
XML can only be enabled if Email is enabled.
The Email and XML options are available to be set against the transaction entry (e.g. Purchase Order) and the process batch options.
The security profile will control, at every menu level, whether a User can have access to XML and Email facilities. By creating the profiles carefully, administrators will be able to determine whether documents can be sent by XML at time of creation or only from a batch approval process.
