Security Controls

User Setup and  Maintenance

Available to the system Administrators and Admin users. Administrators can manage all users. Admin users can manage those users whose Home Org falls under their Security Org.

Key Security Fields

Privilege (PROJ/ORG/ADMIN) — Controls which contexts are available to the user.  PROJ users can only see the PROJ context. ORG users can see the PROJ and ORG contexts.  ADMIN users can see the PROJ, ORG, and ADMIN contexts.

Security Org ID — Can be assigned at any level of the Org structure. Primary control of Org visibility for ORG users.  Controls staff available for PROJ users when using the budget functions.

Labor Suppress (Y/N) — When set to Y, the user will not be able to see raw labor costs by employee. When set to N, all cost information is visible.

User Security Group — Assign a user to a specific security group. You can create User Security Groups to further restrict access to an organization, module, or application, but you cannot use them to expand access beyond that which is already granted by the license type. Learn more about User Security Groups.

Special Organization Reporting Rights (COM2, MA07, BOM2)

Available to system Administrators, Admin and Org users. Administrators can delegate rights to any org level for all users. Admin users can delegate rights to any org they have rights to see for users whose Home Org falls under the Admin user’s Security Org. Org users can delegate rights to any org they have rights to see.

Rights granted through the Special Organization Reporting Rights option supplement the rights an Org user has based on their Security Org. These additional rights increases the orgs listed in the Organization Navigation list boxes, as well as the Projects listed in the Project Navigation list boxes. The additional rights also expand the staff available to use in the drop-down list in the Project Budget tool.

Org Budget Approvers/ Managers (MA03)

Available to system Administrators and Admin users. Users set up as an Org Budget Approver can approve budgets for any org that falls under the org for which they are setup as an approver. They can also create budgets at any lower level org that fall under the org for which they are setup as an approver.

Org Budget Managers are assigned at the lowest level of the org. Users set up as an Org Manager can create Org Budgets for orgs for which they have been set up as Manager.

Project Mgr Assignment in ERP

By default, both Org and Proj users have rights to see projects they have been assigned as the Project Manager for in Costpoint or GCS Premier. They have full rights to any tasks below the level where they have been set up as Manager. The user also has partial rights to parent levels of the projects they manage.

Additional Project Level Reporting (CPM2, CPM3)

Available to all Org and Project users. Existing Managers with full rights to a project can delegate reporting rights to any other user. Once a user has received reporting rights, they can then also delegate rights to other users.

The reporting rights grant visibility to view pages related to those projects, as well as budget creation rights to those projects. Additional Project Level Reporting Rights supplement the list of projects available to a user as defined by the other project rights mechanisms.

User Security Groups (MAU12)

Available to the system Administrators and Admin users. The User Security Group feature enables you to create separate menus for a single user or group of users.

Maintain Project Exclude Rights for Users (MAP10)

Available to system Administrators and Admin users. Allows the administrator to identify specific projects that should not be seen by specific users. These rules act as a final modifier to the Project rights created based on all other Project Rights mechanisms and removes the identified projects from the user’s Navigation, preventing visibility into any details for that project and all children of that project.

Add Project Mgr Matrix Rights (MAP9)

Available to system Administrators and Admin users. Allows administrators to identify staff that should be available to a user for Project budgeting purposes, based on Home Org, in addition to the users rights based on their Security Org.