Apply Data Filters and Object Security
The semantic model dynamically applies both object security and row-level data filters during query generation.
Object Security (Subject Area Access)
Duty roles determine which subject areas users can access. For example, the authorized subject areas can be:
- OBIA EBS Financials - AP Balance
- OBIA EBS Financials - AP Holds
- OBIA EBS Financials - AP Invoice Aging
Object security ensures users can see only the subject areas and analytics objects assigned to them.
Data Security Filters
Data roles determine which data rows users can access. For example, a data filter can be as follows:
| Dimension | Operator | Value |
|---|---|---|
|
Operating Unit |
IN |
@ORG_BU |
Security Enforcement
The semantic model automatically applies the following during query execution:
- Object security filters
- Row-level security filters
The same framework can support multiple dimensions and combinations of dimensions.