Apply Data Filters and Object Security

The semantic model dynamically applies both object security and row-level data filters during query generation.

Object Security (Subject Area Access)

Duty roles determine which subject areas users can access. For example, the authorized subject areas can be:
  • OBIA EBS Financials - AP Balance
  • OBIA EBS Financials - AP Holds
  • OBIA EBS Financials - AP Invoice Aging

Object security ensures users can see only the subject areas and analytics objects assigned to them.

Data Security Filters

Data roles determine which data rows users can access. For example, a data filter can be as follows:
Dimension Operator Value

Operating Unit

IN

@ORG_BU

Security Enforcement

The semantic model automatically applies the following during query execution:
  • Object security filters
  • Row-level security filters

The same framework can support multiple dimensions and combinations of dimensions.