AugForums.com

An Acumatica User Group

  • Free
    • Start Here
    • In-Person Gatherings
    • Power BI Workshop
    • Podcast
    • Rolodex
    • Blog
    • Forums
  • Paid
    • AugSQL
    • GI Course
    • GI Library
    • Consulting
  • Register
Acumatica Forums

By using this website, you agree to our Terms of Use (click here)

Forums
AUG Forums
Everything Else
Site Map and Defaul...
 
Notifications
Clear all

Questions Site Map and Default security Access

 
Everything Else
Last Post by Tim Rodman 6 years ago
7 Posts
3 Users
1 Reactions
3,761 Views
RSS
SQLRunner
Posts: 45
 SQLRunner
Topic starter
January 29, 2018 12:40 pm
(@sqlrunner)
Trusted Member
Joined: 8 years ago

Good Morning Everyone,

Today I'm looking at the site map and reviewing how it works with security roles.  I understand that within security roles I can revoke, grant, etc on target screen.  I created a new dashboard option at the top level. It is the "IC Dashboards" in the screenshot.  It appears that by default, users are given access to this new section.  This would indicate that every time I add  a new item to the sitemap that does not inherit from a parent, I would be forced to change roles to grant or revoke.  I kind of support the Linux approach, which is stuff locks by default until access is granted.  Is this expected?  Is there a setting that dictates default behavior?  Thanks in advance for any guidance.


6 Replies
Tim Rodman
Posts: 3204
 Tim Rodman
Admin
January 31, 2018 11:03 pm
(@timrodman)
Famed Member
Joined: 11 years ago

I agree with you, it should be revoked by default.

But I have noticed the same behavior as you with ANY Site Map entry, not just Dashboards. You have to assign some kind of security permission to at least one User Role. If you leave "Not Set" in all of the User Roles, then it will be available to everyone.


Reply
SQLRunner
Posts: 45
 SQLRunner
Topic starter
February 1, 2018 10:41 am
(@sqlrunner)
Trusted Member
Joined: 8 years ago

Hi Tim,

Thanks again for the information.  I realized some default open security had to be taking place, otherwise you would lock yourself out immediately.  Thanks again.


Reply
Tim Rodman reacted
Tim Rodman
Posts: 3204
 Tim Rodman
Admin
September 4, 2019 9:20 pm
(@timrodman)
Famed Member
Joined: 11 years ago

This really should be fixed. I created an idea that you can vote on:

https://feedback.acumatica.com/ideas/ACU-I-2456


Reply
Royce Lithgo
Posts: 557
 Royce Lithgo
September 5, 2019 3:45 pm
(@roycelithgo)
Honorable Member
Joined: 6 years ago

Personally i think it's ok the way it is. For example, we had a big upgrade earlier this year implemented by our partner. During that upgrade, new screens were added. All of these screens were initially viewable by all. This allowed us to easily review the new functions and then apply appropriate security roles to secure them as needed. 

It also means users can publish ARM reports themselves without asking IT (me) to configure security for them. Much better than them publishing a report and then not seeing it on the menu at all.

Once you understand that any Site Map item that hasn't been explicitly secured is globally accessible you adapt as needed. 

It's really only a trap for new players.


Reply
SQLRunner
Posts: 45
 SQLRunner
Topic starter
September 5, 2019 3:59 pm
(@sqlrunner)
Trusted Member
Joined: 8 years ago

It is the reverse of what you typically find in tech products.  In many products it is very limited by default and you open things up to whomever needs them.  Either scenario is functional if the admin knows how to control the software.  The reason tech usually chooses the more secure route is because the "oops" are noticed when an individual has a viable need to access a resource and lets you know that they can not access the resource.  The default open results in a "oops" an employee is now upset because of sensitive information that they were not suppose to see was open. Or oops a bunch of sensitive information was exposed.  That is the difference.  

I think Acumatica went this route, not because it was the typical route (its not), but they did not want to immediately upset customers who did not know how to effectively implement security roles.  In the event, information was exposed, you can always rebuttal to set the application correctly then and grab a consultant if you can not.  Versus, a new customer that is getting upset before commitment because they cant access anything and do not know how to set it and decide to walk away from the product.  

 

Just my guess.  I think the site map security roles needs some enhancements in any case.  i.e. a select all button, so that you are not going field by field by field...

 

 

 


Reply
Tim Rodman
Posts: 3204
 Tim Rodman
Admin
September 28, 2019 7:11 pm
(@timrodman)
Famed Member
Joined: 11 years ago

Royce,

Regarding ARM reports, I hadn't thought about that. Maybe there could be a setting in the General Ledger Preferences screen for a Default User Role for any new ARM reports. Then you could setup a User Role for ARM report creators and make that the default for any new ARM reports.


Reply
Forum Jump:
  Previous Topic
Next Topic  
Forum Information
Recent Posts
Unread Posts
Tags
  • 12 Forums
  • 2,531 Topics
  • 11 K Posts
  • 27 Online
  • 2,418 Members
Our newest member: Chad Treadwell
Latest Post: Upgrade to 2025.2 Custom Report Run Report is missing
Forum Icons: Forum contains no unread posts Forum contains unread posts
Topic Icons: Not Replied Replied Active Hot Sticky Unapproved Solved Private Closed

Online Members

  • Dianne A amassey
Acumatica Forums

Terms of Use & Disclaimers :: Privacy Policy

Copyright © 2026 · AUG Forums, LLC. All rights reserved. This website is not owned, affiliated with, or endorsed by Acumatica, Inc.

‹›×

    ‹›×