Process Permission Group Policy
Permission group policies must be processed after security changes so that role assignments and data-access permissions are applied to Payables Agent pages.
| When to process permission group policies | Why it matters | Validation |
|---|---|---|
| New Payables Agent users are provisioned | Applies role and permission group assignments. | User can access assigned Payables Agent pages. |
| New Payables Agent privileges are added to a role | Applies updated page or action access. | User can perform the newly assigned activity. |
| Business Unit access is assigned or changed | Applies invoice data security. | User sees only invoice data for assigned Business Units. |
| Custom roles are created or updated | Applies role changes to affected users. | User access matches the updated role design. |
| Users report page access but no data | Ensures permission group and data security changes are applied. | User can view authorized invoice records after processing. |
Security roles for Payables Agent must be compatible with the permission-group-based architecture. Data access must be granted through roles enabled for permission groups, and Business Unit security must be assigned with those roles. Don't assume that data security from classic roles applies automatically to Payables Agent features.