Security Groups (SP) ApplicationYou set up security privileges by group. You use the Security Groups (SP) application to create groups and then you specify group privileges and restrictions for applications and options, as well as other settings.
You grant users security rights by assigning them membership in one or multiple groups. You can assign users to groups from both the Security Groups (SP) and Users applications:
In the Security Groups (SP) application, you assign users to groups.
In the Users application, you assign groups to users.
The combination of groups to which a user belongs determines his or her security profile. You can view a user's security profile graphically on the Security Profile tab in the Users application.
The Security Groups (SP) application has the following four groups set up:
DEFLTREG - allows a user to change his or her password if it expires. It contains no other rights. When you insert a new Users record, the system places the user in this default group. You can specify a different group to be the default using the Security Controls window.
MAXADMIN - allows a user to add users and groups.
MAXREG - allows users to self register. You can use MAXREG to initiate a workflow process by which an administrator receives an alert when users register and can assign the new users to the appropriate security groups.
EVERYONE - used for global settings that apply to all users in the system.
You must create additional groups, with different sets of rights, to be able to assign users different sets of privileges. If you want new user security profiles to start with more rights, you can modify the DEFLTREG group to include those rights. Using LDAP (Lightweight Directory Access Protocol) with the system requires special consideration. Consult the System Administrator's Guide for information on integrating the system with LDAP.
The Security Groups (SP) application contains the following tabs:
List: to search for group records.
Group: to add a new group, specify its start center, and specify whether or not the group rights are independent of other groups.
Sites: to specify which sites a group has access to in a multisite implementation.
Applications: to specify which applications and options a groups has rights to.
Storerooms: to specify which storerooms a group has access to.
Labor: to specify which labor records a group can view.
GL Components: to specify which GL components a group can change.
Limits and Tolerances: to specify various purchasing, requisitioning, and contract limits and invoice, tax, and service tolerances.
Data Restrictions: to restrict access to certain data fields and certain functions in applications.
Users: to assign users to groups and view existing group membership.
Customers: To specify the type of customer authorization users in the security group are assigned, and which customers they can access (depending on the type of authorization).
If the implementation uses an application server to authenticate with a directory, some functions will be performed in the directory and synchronized into the system. These functions may include:
Adding users (including self-registration)
Adding security groups
Associating users with security groups
Managing passwords
Strategies for Creating Security Groups