Strategies for Creating Security Groups

You use the Security Groups (SP) application to create security groups. Security groups vary, depending on the number of sites in your company or facility, and depending on how fine-grained you want your security privileges. For a detailed discussion of how security works in the system, refer to the Security chapter in the System Administrator's Guide.

Roles

A security group grants the privileges for a user to act in a role such as help desk operator, customer administrator, billing specialist, or purchasing specialist. Multiple security groups work together to provide all of the privileges that allow a user to perform that role. For example, a customer administrator is in two security groups; one specifies the applications that he or she can access and one specifies the customers that he or she can access. Another customer administrator is in the same security group that specifies application access, but in a different security group that specifies customer access, since the second customer administrator is authorized access to a different group of customers.

Sites

The security architecture is designed to use sites as the first level of security for multisite implementations.

Note: If you select the Independent of Other Groups check box on the Groups tab, you must grant that group access to at least one site and one application unless the group is being used exclusively for system-level applications.

Applications, Storerooms, Labor, GL Components, Limits and Tolerance, and Restrictions

The above items represent other tabs in the Security Groups (SP) application. There are basically two strategies here:

You can also create groups that use a mixture of these two approaches. It all depends on how you want to implement security.

Combining Groups

The virtue of creating many groups is being able to combine them in many ways to fashion individual security profiles. A major attribute of a group is whether it is Independent of Other Groups. This attribute is a check box on the Group tab. By default the system has this check box cleared, meaning the group is non-independent and that you combine privileges when you combine groups. If you select the check box, the system will not combine privileges; the group is independent.

Basically, when you combine privileges, the highest privilege wins. If a user belongs to multiple groups that define the same privilege at different levels, the user possesses the highest privilege. For example, if group A has a PO limit of $5,000 and group B has a PO limit of $10,000, then a user who is a member of both groups A and B has a purchasing limit of $10,000.

Combining privileges becomes more useful as an implementation strategy when you have multiple sites. Typically, you set up groups that only define site access, for example, SITE1, SITE2, and SITE3. You define other groups to define application privileges, purchasing approval limits, and so forth. If you have a user for whom you have created a security profile that includes SITE1 and a number of other groups to define application privileges and so forth, and you want the user to have the same privileges at SITE2, you simply add SITE2 to the user's profile. He or she will have the same rights in SITE2 and in SITE1.

On the other hand, you may want to define some groups as independent so that when you combine groups, a user has one set of privileges at one site and a different set of privileges at another site.

For detailed information on creating independent and non-independent groups, the rules for combining and merging groups, and the affect the application level (organization versus site, for example) has on merging groups, refer to the Security chapter in the System Administrator's Guide.

Note: You can use the default group EVERYONE, to configure global settings which apply to all users of the system. This group always combines with other groups.

See Also

Security Groups (SP) Application

About Security Profiles

Add a Group