Configure Business Unit Data Security
Page or action access controls what users can open.
Business Unit data security controls which invoice data users can see and act on. Users who review invoice documents, manage invoice exceptions, download source documents, or correct invoices must be assigned access to the appropriate Business Units.
Any custom job roles assigned with the new invoice-related duty roles must also be granted Business Unit data security access. Otherwise, users cannot view invoice details.
Configure Business Unit data access using the Manage Business Unit Data Access for Users task. Assign the user, role, and Business Unit combination, then process permission group policies. The source security guidance confirms that users need Business Unit security to drill down from Streams to Invoice List, view invoices, and search invoices directly from Invoice List.
To configure business unit data access:
- Go to .
- Select the user.
- Select the custom role.
- Grant access to the required Business Units.
- Process Permission Group Policies.
- Save your changes.
- Verify completion.
After Business Unit access is configured and permission group policies are processed, confirm that users can view invoices for their assigned Business Units. Users should also be able to search invoices in Invoice List, drill down from Invoice Document Streams to Invoice List, and open invoice details for authorized Business Units.