Master Data Management

Set a Role's Org Unit Value Assignments

A Security Administrator can include or remove multiple org unit values at one time for all of the roles in a position . With this option it is not necessary to configure the org unit values for each individual role in a position.

Roles are added to categories in Master Data Management > Design. Org unit values differ by category and therefore must be configured separately for each category included in a position and are applied only to the roles in the category.

NOTE: Category org units become available for security assignment in a position when the business process assigned to a category is included the position.

Refer to Add an Org Unit Type to a Category Object and Add a Role for more information about setting up org units for a Category and adding roles to a category.

The category org unit value configuration functions as a template for org unit value assignment to a role in the position. Any role that is added to the position that belongs to the category for which the org unit is established is automatically assigned the org unit values that are included on the Position Category OrgUnit page. Any roles that exist for a position are updated with the org unit values that are included or removed when the Position Category Org Unit page is updated. However, roles can be configured individually if needed. Refer to Configure Org Unit Value Assignments for Roles at the Role Level for more information.

Configure Org Unit Value Assignments at the Position Level

Before performing this task, design the governance elements in Master Data Management > Design and add a position. Refer to MDM Design Process Overview and Add a Position for more information.

To configure org unit value assignments at the position level:

  1. Select Master Data Management > Security > Positions in the Navigation pane; the Position page displays.
  2. Click the Category Org Units icon; the Category Org Units for Position page displays in the child pane.

    View the field descriptions for the Category Org Units for Position page

  3. Click the Org Unit1 icon for a CATEGORY ID.

    View the field descriptions for the Position Category OrgUnit1 page

  4. Select one or more org unit values.
  5. Click the Include or Remove icon as needed.

    If Include All Org Units on the Category Org Unit Type page is turned on, the '*' org unit value is available to be included. This allows the user to assign all the org unit values for all roles within a category that are assigned to the position.

  6. Repeat steps 3– 5 to add Org Unit2 and Org Unit3 values as needed.

View the field description for the Position Category OrgUnit2 page

View the field description for the Position Category OrgUnit3 page

NOTE: If you do not see all included Org Unit values on the Category Org Units for Position page, click the Refresh Values icon.

Next, configure org unit value assignments for roles at the role level if needed.

Configure Org Unit Value Assignments at the Role Level

Users assigned to a position have access to the data that corresponds to the org unit values configured for the roles included in the position. A template for the org unit values that are included or removed for roles is configured on theCategory Org Units for Position page. Optionally, org unit values to be included or removed for an individual role can be customized on the Position Role Org Unit page using the following steps.

Before performing this task, design the governance elements in Master Data Management > Design and add a position. Refer to MDM Design Process Overview and Add a Position for more information.

To configure org unit value assignments for roles at the role level:

  1. Select Master Data Management > Security > Positions in the Navigation pane.
  2. Click the Roles icon for a position.

    View the field descriptions for the Position Role page.

  3. Click the Org Unit1 icon.
  4. Click Add.

    View the field descriptions for the Position Role Org Unit 1 page.

  5. Select the org unit value in the Position Role Org Unit list box. 
  6. Click Save.
  7. Repeat Steps 3 – 6 to add Org Unit 2 values and Org Unit 3 values as needed.

View the field descriptions for the Position Role Org Unit 2 page.

View the field descriptions for the Position Role Org Unit 3 page.

Next, configure the read-only/editable settings for org unit value assignments for roles if needed

Configure the Read-Only/Editable setting for Org Unit Value Assignments for Roles

For a role, a user has access to the data that corresponds to the org unit values included in the role. In a position, a System Administrator can set read only and editable setting, if needed.

If a role is set to read only on the Position Role page, every org unit value assigned to the role is set to read only. However, If one of the org unit values is set to editable on one of the Position Role Org Unit pages, the role is set to editable in the position.

The settings control whether or not a user assigned to the position for this role can edit and take action on the org unit data in the Content WebApp.

A user can be assigned to multiple positions. The security setup uses the most permissive setting for users across their assigned positions. If a user is assigned to two positions, one in which a role has an org unit value that is set to read only, and one in which a role has the same org unit set to editable, then the user is considered to have editable access for that org unit value.

Before performing this task, design the governance elements in dMaster Data Management > Design and add a position. Refer to MDM Design Process Overview and Add a Position for more information.

To configure the read-only or editable setting for org unit value assignments:

  1. Select Master Data Management > Security > Positions in the Navigation pane.
  2. Click the Roles icon for a position.

    View the field descriptions for the Position Role page.

  3. Click the Org Unit1,Org Unit2, or Org Unit3 icon as needed.
  4. Select one or more org unit values and then click the Set as Read Only or Set as Editable icon as needed.