Control Data Access by Role

To control what data is visible to users, create a mapping between a data profile and a role.

When users sign in, they see only those parts of data from the business object that their role has access to, through the data profile.

Note: If you created a custom role by copying a delivered role, remove all data security policies that were copied from the delivered role. You can assign and manage all data access through data profiles by using the Manage Application Access task.

To set up data access:

  1. Sign in as IT Security Manager.

  2. From Student Central, click Search and search for Application Access.

  3. Click Data Profiles.

  4. Click New Data Profile.

  5. Specify a name and description for the profile.

  6. Select a business object. To see the fields associated with that business object, click inside the Fields field.

  7. Select the fields whose values will define the data access to this profile. You can add as many fields as you need to.

  8. When you're done, click Save. The data profile you created is displayed on the list.

  9. Click the ellipses on the row for the data profile you just created, and click Assign to Roles. If you don't see the ellipses, scroll to the right.

  10. On the Assign Data Access to Roles page, click Add Role, select a role to add to the data profile, and click Add.

  11. For each of the fields that you enabled for the data profile, select the values to define the security filter conditions on the data set for the business object.

    The list of values for dependent security condition fields are filtered based on the values selected on previous fields. That is, a driving field or column is ordered to the left of a dependent field or column, so that the values in the dependent field are filtered based on the values from the driving column.

  12. When done, click Add.

  13. Use the Add Row option to add more security filter conditions on the data set for the business object. All of the security conditions rows are aggregated to define the data set from the business object that this role has access to.

  14. When done, click Save.