Loading...
Financial Management
HFM
Hyperion
Hyperion Financial Management
Hyperion FM
Online Training
Oracle
Oracle HFM
Security
VirtualNuggets
https://oraclehyperionfinancialmanagement.blogspot.com/2015/08/oracle-hfm-security-class.html
we found a post on the Oracle HFM forum where someone had two screenshots of from
security and asking about the difference in them. One screenshot had the
[Default] class set to ALL and the other screenshot had the (Default) class set
to NONE. What's the difference and why is this important? For those who have
not taken the 123OLAP HFM Administrator Boot-camp training class with my manual, here are the details.
In HFM security
classes are used to link metadata elements and various artifacts (data grids,
data forms, journals, etc.) to users and/or groups with some level of access
(NONE, READ, ALL, etc.). When a class isn't assigned to something, then the
built-in [Default] class is used by the software. From a design standpoint,
there are two primary ways of working with this behavior.
1) Give users ALL
access to [Default]. If something isn't specifically secured then it's open for
the users to modify, assuming everything else allows that.
2) Give users NONE
access to [Default]. If something isn't specifically secured with access
granted then it is not available to the users.
3) You could do
something weird like give users one of the other levels of access to [Default]
(Metadata, Read, or Promote) but really they're just variations on (2).
By far, number (1)
is the preferred security design. The administrator secures what should be
secured and everything else is left open. This design reduces the work in the
initial setup and in ongoing maintenance. Also, and this is big, end users
don't have to worry about security. If they create a HFM journal, ideally they
assign a security class to it that relates to the entity being adjusted (ie,
show the Canada journal to only the Canadians and not everyone else). BUT, if
they don't assign a class, then with (1) they can still see the journal, edit
it, etc. Under (2), if they don't assign a class to the journal then when they
save the journal will appear to disappear: it's been correctly saved, but
security is not letting them see it.
For some new administrators
this can be a tough concept. If you're setting up security on a network
firewall, you close all the network ports and open only those that are needed,
right? But for HFM, it works best (and its widely done this way) to leave
everything open and secure only the necessary metadata/artifacts.
Financial Management,
HFM,
Hyperion,
Hyperion Financial Management,
Hyperion FM,
Online Training,
Oracle,
Oracle HFM,
Security,
VirtualNuggets
VirtualNuggets
4671660455923087324
Post a Comment
Home
item
Popular Posts
-
What are different ways of running consolidation in HFM? Consolidate- will consolidate only what has changed from the previous executi...
-
One of the somewhat newer and lesser used features is the equity pickup module. I've set it up twice and in the middle of a third time...
-
Oracle Hyperion Financial Management is a packaged solution for finance users that helps develop standardized financial data m...
-
we found a post on the Oracle HFM forum where someone had two screenshots of from security and asking about the difference in them. One sc...
-
Oracle Hyperion Financial Management (HFM) is a packaged solution for finance users that helps develop standardized financial data managem...
-
1. What is HFM? Ans: Oracle Hyperion Financial Management is a financial consolidation and reporting application built with advanced W...