Go to primary content
Siebel CRM Siebel Security Guide
Siebel Innovation Pack 2016, Rev. A
  Go to Documentation Home
Go To Table Of Contents
Go To Index

    View PDF

Implementing Access-Group Access Control

This topic describes the administrative tasks you must perform to implement access-group access control.

To implement access-group access control perform the following tasks:

About Administering Catalogs of Data

You can do the following catalog and category administration tasks in the Administration - Catalog screen:

  • Create and delete catalogs and categories of master data.

  • Associate data with categories.

  • Modify the hierarchical position of a category within a catalog.

For information about creating and administering catalogs, see Siebel eSales Administration Guide and Siebel Partner Relationship Management Administration Guide.

Key principles for setting up a catalog include, but are not limited to:

  • Set the Catalog Type field to allow display of the catalog in certain Siebel customer or partner applications, in addition to Info Center and Info Center Explorer in Siebel employee applications. For example, set the Catalog Type to Partner to display the catalog in Siebel Partner Portal, as well as in Info Center.

  • Make sure the Active flag is set and the Effective Start Date and Effective End Date fields provide visibility of the catalog during your intended time interval.

Related Topic

"Implementing Access-Group Access Control"

Administration Tasks for Positions, Organizations, Households, and User Lists

Access groups are made up of positions, organizations, households, and user lists. This topic describes the administration tasks associated with each of these access groups.

About Administering Positions

Perform the following administrative tasks for positions:

About Administering Organizations

The Organization group type includes organizations, divisions, and accounts. You must perform the following administrative tasks for organizations:

  • Create divisions and accounts.

    For information on creating divisions, see "Setting Up Divisions". For information on creating accounts, see Siebel Applications Administration Guide.

  • Promote divisions to organizations and maintain division hierarchies.

  • Associate positions with divisions and with partner organizations.

For information on creating organizations, see "Setting Up Organizations". For information on planning for organizations, see "About Organization Access Control" and "About Planning for Organizations".

About Administering Households

You must perform the following administrative tasks for households:

  • Create households.

  • Associate contacts with households.

  • Maintain household data.

For information on these tasks, see Siebel Applications Administration Guide.

Administering User Lists

You can group arbitrary users into user lists for the purpose of granting them access to data through access groups. Users in this context include contact users, employees, and partner users. For information about user lists, see "Access Control for Parties".

The following procedure describes how to create a user list and add users to it. You can delete users from a user list similarly.

To create a user list 

  1. Navigate to the Administration - Group screen, then the User Lists view.

    The User Lists list appears.

  2. In the User Lists list, add a new record.

    A new user list record appears.

  3. Enter a name for the user list. Optionally, change the default entry for Group Type.

  4. Save the record.

  5. To add users to the user list you created, select the list.

  6. In the Users list at the bottom of the view, add a new record.

  7. Select one or more users, and then click OK.

    The selected users appear in the Users list. If a user, such as a customer user, belongs to an account, the Account field populates automatically.

Related Topic

"Implementing Access-Group Access Control"

Administering Access Groups

You can group parties of types Position, Organization, Household, and User List into access groups for the purpose of controlling their individual members' access to data.

You administer access groups in the Administration - Group screen. This screen contains the Access Groups tree and the Access Groups list.

The Access Groups tree lists all access groups on the second level of the tree. Each access group can be expanded to show its descendants. Therefore, an access group can appear at different levels in multiple branches of the tree. An access group that has no parent access group is the top node of an access group hierarchy. For information about access groups, see "Access Control for Parties" and "About Access-Group Access Control".

Creating an Access Group

The following procedure describes how to create an access group.

To create an access group 

  1. Navigate to the Administration - Group screen, then the Access Groups view.

    The Access Groups tree and the Access Groups list appear.

  2. In the Access Groups list, add a new record.

    A new access group record.

  3. Complete the following fields, then save the record. Use the guidelines below.

    Field Guideline
    Name Required. Provide a name for the access group.
    Group Type Pick Access Group or Partner Community. These labels denote conceptual differences. Functionally, they are the same.
    Parent Access Group Specify a parent access group from which this new group inherits access to data that the parent group has access to.

    The new access group also appears in the Access Groups tree.

Modifying an Access Group

You can modify an access group by adding or deleting members using the following procedure.

To add members to an access group 

  1. Navigate to the Administration - Group screen, then the Access Groups view.

    The Access Groups list appears.

  2. In the Access Groups list, select an access group.

  3. In the Members list, add a new record.

    A pop-up list appears that contains positions, organizations, accounts, households, and user lists.

  4. Select one or more members, and then click OK.

    The selected members appear in the Members list.

  5. In the Access Groups list, save the record.

You can delete members from an access group similarly.

Modifying an Access Group Hierarchy

You can modify the hierarchy of an access group by changing an access group's parent as described in the following procedure.

To modify a hierarchy of access groups 

  1. Navigate to the Administration - Group screen, then the Access Groups view.

    The Access Groups list appears.

  2. In the Access Groups list, select an access group.

  3. Click on the Parent Access Group field.

    The text box becomes editable and its entry is highlighted.

  4. Do one of the following to modify the hierarchy:

    • To make the access group the top node of its own hierarchy, delete the entry in the Parent Access Group field. Click Save.

    • From the Parent Access Group field, pick a new parent and click OK. Click Save.

    The Access Group tree is updated to reflect the access group's new position in a hierarchy.

Related Topic

"Implementing Access-Group Access Control"

Associating Access Groups with Data

The individual users in an access group are provided access to data by associating the access group with catalogs or categories of data.

Be aware of the following user interface behaviors related to associating an access group with a catalog or category:

  • Access inheritance. When you associate an access group with a category, its descendant groups are also associated with the category. However, this inheritance is implemented at run time, and is not represented in the database. As such, the descendant access groups associated with the category are not displayed in the list of groups associated with the category.

  • Cascade button. Clicking the Cascade button provides the given access group with visibility to all of the child categories of the current catalog or category. Clicking this button repeatedly has no effect. You must manually disassociate the group from the child categories to undo the access cascade.

  • Private catalog. If you specify a catalog to be private, its categories are all set as private. If you remove privacy at the catalog level, the categories retain privacy. You must then set or remove category privacy individually.

Associating an Access Group with a Catalog

By associating an access group with a catalog of master data, you grant access to the data in the catalog to individual users in the access group.


For a catalog and all of its categories to be visible only to the access groups associated with it, the catalog's Private flag must be set.

To associate an access group with a catalog 

  1. Navigate to the Administration - Catalog screen, then the Access Groups view.

    The Catalogs list appears.

  2. Select a catalog.

  3. In the Access Groups list, add a new record.

    A pop-up list appears that contains access groups.

  4. Select an access group, and then click Add.

    The access group appears in the Access Groups list.

  5. In the Access Groups list, save the record.

  6. Select an access group, and then click Add.

    The access group appears under the Access Group tab.

  7. Complete the following fields, then save the record. Use the guidelines provided below.

    Field Guideline
    Admin Set this flag to allow users in this access group to administer the catalog.
    Cascade Set this flag to automatically associate this access group with the catalog's descendant categories (child, grandchild, and so on). The resulting behavior is that users in the access group have access to the data in the descendant categories.

You can disassociate an access group from a catalog similarly.

Associating an Access Group with a Category

By associating an access group with a category of master data, you grant access to the data in the category to individual users in the access group.


For a category and all of its subcategories to be visible only to the access groups associated with it, the category's Private flag must be set or the Private flag of the catalog or a category from which the category descends must be set.

To associate an access group with a category 

  1. Navigate to the Administration - Catalog screen, then the Access Groups view.

    The Catalogs list appears.

  2. Drill down on a catalog name.

    The Categories list for the catalog appears.

  3. Click the Access Groups view tab.

  4. In the Access Groups list, add a new record.

    A multi-value group appears that lists access groups.

  5. Select an access group, and then click Add.

    The access group appears in the Access Groups list.

  6. In the Access Groups list, save the record.

  7. Select an access group, and then click Add.

    The access group appears under the Access Group tab.

  8. Complete the following fields, and save the record. Use the guidelines provided below.

    Field Guideline
    Admin Set this flag to allow users in this access group to administer this category.
    Cascade Set this flag to automatically associate this access group with this category's descendant categories (child, grandchild, and so on). The resulting behavior is that users in the access group have access to the data in the descendant categories.

You can disassociate an access group from a catalog similarly. When an access group is disassociated from a category, it is automatically disassociated from all of the category's descendant categories.

Related Topic

"Implementing Access-Group Access Control"