Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Anchor_Toc455648777_Toc455648777 Anchor_Toc472062215_Toc472062215 Anchor_Toc476559014_Toc476559014 Anchor_Toc481571878_Toc481571878 Anchor_Toc483991087_Toc483991087Create and manage roles


Wiki Markup
Roles and authorisations are managed in the Master Data dialogue _Roles{_}. The role concept implemented in the GTC allows a differentiated control over the data access. This concept supports the four-eye principle for the data quality assurance. All available roles are listed in the dialogue overview. 
A role is the combination of several authorisations – initially without certain assignment to companies. The authorisations created in the _Roles_ dialogue can be assigned in the _User_ dialogue.  

*Name \[* !worddav75885e27e924d844222af95456b48ec1.png|height=12,width=12! *\]*
After clicking on the \[ !worddav7255a5dba5e0f1f0c6e1ea6abb2e8b9a.png|height=23,width=55! \] button, a subdialogue opens, here you can enter the name for the new role. The roll name is freely selectable and can be changed at a later date.
!worddav73ed897e902033470e2a3ba2014586ff.png|height=103,width=368!
_Figure 20: Create a new role_

The ID is assigned automatically by the GTC.

*Authorisations \[Object-Value\]*
When the role is created, authorizations can be assigned. For this purpose, use the available drop-down menu. The selection list shows all possible combinations of objects \[e.g. _Master Data{_}\] and values \[{_}Read{_}, _Edit{_}\].
!worddavf0cb4145e9a00bab75615e69cd8a069c.png|height=78,width=646!
_Figure 21: Assign authorisations to the created role_

An overview of the possible object-values and the associated authorizations or properties can be requested from AMANA. The plus symbol allows you to assign multiple authorisations to a role.

*Cascading*
If the _Cascading_ checkbox is activated, the selected authorisation is assigned cascading \[attribute is thus only relevant for the company-specific authorisations\]. For example, if the user is assigned the right to edit the balance sheet comparison for the parent company in the _User_ dialogue, this authorisation also applies to subordinate companies. Such situation is typical for a subgroup: the subgroup manager does not need to have a separate role for each subgroup company. The role must only be assigned to the parent company and then _cascaded_ for all subordinate companies.