MSAMM
Back to course

Implementing Global HR: From Enterprise Model to Live Workforce · Module 2 · Security and Role Provisioning

What breaks

Lesson 20 of 175 · 5 min · Free preview

"This user cannot see a worker they should see." Check in this order. One: was the role regeneration process run after the last change? First, always, because it is the most common. Two: does the data role carry a person security profile at all — a role built in a hurry, with function security and no data scope, produces exactly this symptom. Three: do the profile's criteria actually include that worker today? Four: if it is manager-hierarchy based, is the manager relationship on the assignment correct and current? Five: is the worker's assignment status one the profile includes? Six: is there an effective-date issue — is the record future-dated? Then seven failures. The manager sees no direct reports — the manager is not populated on the assignment, or the levels are set to zero; and note where the manager lives, on the assignment rather than the person record, which is

This lesson is free

Watch the full lesson, with its written notes, without an account. It is one of the free lessons this course opens with.

Watch the full lesson

Get the free lessons by email

We will email you a link to every free lesson in this course. No account needed, and one message only.

In this module: Module 2 · Security and Role Provisioning

  1. 1Why HCM security is different
  2. 2Security profiles: the six types
  3. 3Building person security profiles
  4. 4Organization, position and LDG profiles
  5. 5HCM data roles
  6. 6Areas of responsibility
  7. 7User and role provisioning
  8. 8Data protection by design
  9. 9What breaksFree preview
  10. 10Lab: build the security model for four countries