Controlling Application Access
Basic access to service components is controlled by assigning users to predefined roles in the identity domain.
About Managing Access and Data Security summarizes the Profitability and Cost Management security model.
Additionally, Service Administrators can, from Access Control, create groups made up of identity domain users or other groups. Assigning roles to such groups enables Service Administrators to grant roles to many users at once, thereby reducing administrative overheads.
Assigning roles at the application level can only enhance the access rights of users; none of the privileges granted by a predefined role can be reduced by roles assigned at the application level.
To display the access control features of Profitability and Cost Management, on the Home page, click Tools,  , and then Access Control,
, and then Access Control,  ).
).
               
For information about assigning users to roles and creating groups, see Getting Started Guide for Administrators and Administering Access Control.
The following section, Granting Access to Data, describes how to enable users to access data slices.