Security

Functional Class

Overview

A Functional Class refers to users specified level of access rights to system functionality (e.g. full access, only reports). This is an effective way to ensure that only authorized personnel performs certain functions.
Functional Classes allows users to grant or restrict access to every feature on the system such as screens, reports, etc. The system allows for numerous functional classes to be created which can then be assigned to one or multiple users at a time. Each user can have a variety of functional classes assigned to them to meet their specific needs.

 

Navigation

Admin ► System Security ► Security ► Functional Classes

 

Functional Class screen Fields

Field

Description

ID

Unique identification code, manually entered by users or automatically generated based on parameters.

Description

A short description of the Functional Class.

Features

 Used to add features to the Functional Class.

 

Features

Overview

Through Featues, the functionality of Functional Class is defined by selecting the attributes with regard to every entity of each module. The assignment defines the access rights to the system functionality with regard to every relevant entity of each necessary module by chckin or unchecking the fields.

Expand a selected module by clicking the Select to expand Icon to the desired level, and select the entity to edit the access rights. Users need to select feature which want to Create/Modify. Each flag allows users different levels of permissions in the server. If multiple flags have been selected for a functional class it can be treated as Level 1 or Level 2 priority but not the Administrator. And if all the flags under Application Suit have selected, it can be treated as an Administrator level priority.

 

Feature Flag screen Fields

Field

Description

Allow Current Feature

Allows activating and selecting all the features.

Read Allowed

Allow users only to view the information.

Save Allowed

Allow users only to save the entity or processes.

Update Allowed

Allow users only to update the created entity or processes.

Delete Allowed

Allow users only to delete the existing entity or processes.

Show in menu

Allow users to see the modules and sub-modules in the menu.

 

 

Security Group

Overview

The purpose of a Security Group is to restrict the content that users can see throughout the application. For example, if a security group is created that specifies that a particular user will be able to see all information for Institution 001, then that user will only be able to view the information in Institution 001. Conversely, a Security Group may be created to specify that selected users cannot access a selected dimension.
A security group is composed of Security Group Restriction(s) and Users assigned to it. Users may be indirectly assigned to a Security Group via their User Role, or directly related to the Security Group.
Only a ‘Super User’ or ‘Administrator User’ can create Security Groups.

 

Navigation

Admin ► System Security ► Security ► Security Group

 

Security Group screen Fields and Tabs

Field

Description

Code

Unique identification code manually entered by users or automatically generated based on parameters.

Description

Short description of the Security Group.

Security Group Restriction Tab

The Security Group Restriction Tab is used to include restriction information for the security group.

User Security Group Tab

The respective user for whom the security group is defined is mentioned by this tab. This selected from the lookup button.

 

Security Group Restriction Tab

Overview

Security Group Restriction tab holds one or more restriction or rules related to the Security Group are added from this Tab.

 

Security Group Restriction Tab screen Fields

Field

Description

Restriction Type

Indicates that the restriction type is either “In” or “Not in”.

Context Property Dimension

Used to include Security Context Property Dimension, if necessary.

Support is Null Allowed

If checked, indicates that support is null allowed.

Read OnlyBy default it is Unchecked, If checked, then the user will have access to read, write and update data related to this rule.

 

User Security Group

Tab allows to insert one or more users to Security Group.

For details regarding Users, refer to the link below:-

User

 

 

Security Context

Overview

This screen can only be inquired as it comes as a default setting for the FreeBalance Accountability Suite. This screen is referenced when creating Security Context Property Dimension.
For details regarding Security Context Property Dimension, refer to the link below
Security Context Property Dimension

 

Navigation

Menu ► Support Entities ► Security ► Security Contexts

 

Security Context screen Fields

FieldsDescriptions
CodeUnique identification code of the Security Contexts.
ActiveActive Status - if checked, Security Context is available.
EntityName of the entity for which this context is applicable.
LanguageCountry specific language used to store Description field.
DescriptionList a short description of the Retirement Benefit Plan.

 

Security Dimension

Overview

This screen can only be inquired as it comes as a default setting for the FreeBalance Accountability Suite. This screen is referenced when creating Security Context Property Dimension.

There are four Security Dimension types:

  1. COA Restriction: It will restrict the user to work only on certain codes of different concepts of the Chart of Accounts.
  2. Hierarchical Domain: This restriction can be applied on every entity which has hierarchy structure like ‘Institution’ entity; this dimension applied on ‘Institution’ will allow the user that belongs to a certain Institution Unit, where such Institution Unit has more Institution Units related to it, (child, hierarchy) to have access to the entire structure of Institutions that are related to the Institution Unit that the user belongs to.
  3. Domain Restriction: The security group can be restricted to work only on certain elements of a catalogue within certain entity. As an example, in the Procurement Document entity, the user is allowed to work only in Procurement Document Type (‘RFP’, ’EOI’, ‘RFQ’) notice that Procurement Document Type is an entity referenced in the Procurement Document entity.
  4. Literal Restriction: This restriction allows configuring security according to certain values of an entity. As an example, a restriction on the Fiscal Year entity can be configured where a group of users will have read only access to the previous Fiscal Year.

 

Navigation

Admin ► System Security ► Security ► Security Dimension

 

Security Dimension screen Fields

Field

Description

Code

Unique identification code of the Security Dimension.

Active

If false, the Security Dimension cannot be selected in new transactions.

Security Dimension Type

Select a Security Dimension Type from the drop-down menu. Choices include COA Restriction, Hierarchical Domain, Domain Restriction, and Literal Restriction.

Description

Short description of the Security Dimension.

 

Security Context Property Dimensions

Overview

Security Context Property Dimension integrates Security dimension, security context, and security context property and brings them together. This entity makes reference to Security Dimension and Security Context

For details regarding Security Dimension, refer to the link Security Dimension

and for details regarding Security Context, refer to the link Security Context

 

Navigation

Admin ► System Security ► Security ► Security Contexts Property Dimension

 

Security Context Property Dimensions screen Fields

Field

Description

Active

By default it is TRUE, if checked, Security Context Property Dimensions is available.

Security Dimension

 Possible values are COA, Hierarchical, Domain, Literal to be selected from lookup button.

Security Context

 Refers to the Entity where the Security is being restricted which is to be selected from the lookup button available.

Security Context Property

 It’s the field or property that belongs to the entity referenced in the security context.

 

Security Restriction Configurator

Overview

This screen can be created only by ‘User Administrator’ or ‘Super Users’ (or other authorized users as per government requirements). This screen contains the specific restrictions or rules that will be applied to the selected Security Group.  

For example, if a user belongs to a Security Group and according to Security Dimension type CoA, he/she only has access to the code ‘0101’ of the first segment of the CoA, then that user can only view or enter transactions that are related with Coding Blocks that have ‘0101’ code in the first segment.

 

Navigation

Admin ► System Security ► Security ► Security Restriction Configurator

 

Security Restriction Configurator screen Fields

Field

Description

Security Group

Reference to Security Group. It allows to select the security group from lookup button.

Security Dimension

Contains four Security Dimension types: COA Restrictions, Hierarchical Domain, Domain Restriction, Literal Restriction.

Entity Property Class

Defines the class of the entity property. Select an option from the drop-down menu.

 

Identification Confirmation Configuration

Overview

Identification Confirmation Configuration screen allows enabling password retyping for specific screens in order to enhance security.

Upon opening Identification Confirmation Configuration, users need to select an entity and either enable or disable the Identification Confirmation option as per need. Enabling or disabling the Identification Confirmation configuration may also be done for all the entities.

 

Navigation

Admin ► System Security ► Security ► Identification Confirmation Configuration

 

Identification Confirmation Configuration Screen Fields

FieldsDescriptions
CodeAutomatically selected by the system as per option selected in the first screen.
TypeUsers should select one option out of two option OTP (one-time password) or Use Password Re-challenge.

 

Menu Items

Overview

Menu Item screen shows different informative screens that shows brief information about different items listed in Menu Items. The feature path is mentioned on clicking on the items available on the Menu items screen.

 

Navigation

Admin ► System Security ► Security ► Menu Item

 

Click on Select to Expend icon till option are totally expended and click on child element to view feature path of the child element.

Security Question

Overview

This feature will help the system administrator to store instances of questions to be referred in the Q&A process.

Navigation

Admin ► System Security ► Security ► Security Question

Security Question screen Fields

 

Field
Description
CodeThis is the unique identifier which is auto-generated.
ActiveA checkbox with possible values are True/False. The default value is True.
Description

The description related to the security question.

 

User Security Copy

Overview

User Security Copy screen allows to copy one user's security to another user.

 

Navigation

Admin ► System Security ► Security ► User Security Copy

 

User Security Copy screen Fields and Tab

Field

Description

Source User

In this field, the users have to choose the User from which the User Security is to be copied.

Destination Application Users tab

User have to choose the destination User to which the User Security is to be copied.