MSAMM
Back to course

Implementing Cloud Financials: From Empty Pod to Go-Live · Module 2 · Security and User Provisioning

The security mental model

Lesson 12 of 153 · 1 min

Five links, built from the bottom: privilege → duty role → job role → abstract role → the person. A privilege is the atom — create a journal — and it is never assigned directly. A duty role bundles privileges into a task: journal management. A job role is what somebody's job is: General Accountant. An abstract role is what somebody is, independent of job — employee, line manager, contingent worker — and everyone needs at least one. Job roles inherit duty roles, which inherit privileges. Open the Security Console and expand a delivered accounting role rather than looking at a diagram: the depth of that tree is the point, and it is what people consistently underestimate. Assign job roles and abstract roles to people. Never assign duty roles or privileges directly. Everything else is a maintenance problem somebody inherits, and that somebody is usually you. If the analogy helps:

The full lesson is part of the course

The video, the complete written lesson and the module quiz are included in Implementing Cloud Financials: From Empty Pod to Go-Live, with a certificate on completion and a fourteen-day refund window.

Get the free lessons by email

We will email you a link to every free lesson in this course. No account needed, and one message only.

In this module: Module 2 · Security and User Provisioning

  1. 1The security mental model
  2. 2Function vs. data security
  3. 3The role types
  4. 4Provisioning your first users
  5. 5Data access: ledgers, business units, asset books
  6. 6Building a custom role
  7. 7Segregation of duties
  8. 8What breaks
  9. 9Lab: provision a finance team