Objective:
In this training article we will understand the concept of Data Access Set, why it is required and how to configure it in Oracle Fusion Applications.
What is Data Access Set?
Data Access Set is meant for the security of data. It defines up to what extent the user can use the data, for instance, only for reading purpose OR the user can read and write. In other words it determines the actions that the user can take for a particular data. Data access set defines a set of access privileges to one or more ledgers or ledger sets. The information on ledgers that are attached to data access sets are secured by function security. User must have an access to the segment values associated with the data access sets to access the corresponding GL account.
How the Data access set is used?
If we drill in deep we can see that when we are creating a ledger, it automatically creates a role which gives access to the entire ledger When a Ledger is created, a data access set for that Ledger is automatically created, giving full read and write access to that Ledger. But using manual data access set we can restrict its access to a particular balancing segment. Hence we can say that data access sets are automatically created when we create a new Ledger. We can also manually create data access sets to give read only access or partial access to select balancing segment values in the Ledger. We can combine Ledger and Ledger Set assignments to a single data access set as long as all Ledgers share a common chart of accounts and calendar. When a data access set is created, data roles are automatically created for that data access set. Following five data roles are generated for each data access set, one for each of the Oracle Fusion General Ledger roles-
-Chief Financial Officer
-Controller
-General Accounting Manager
-General Accountant
-Financial Analyst
And the most important thing to remember is that the data roles above must to be assigned to specific users before they can use the data access set.
Configuration of Data Access Set:
Navigate to Manage Data Access Sets under Define General Ledger options from Setup and Maintenance area as shown below-
Click on Manage Data Access Sets
As discussed, when we create ledger or ledger set the system will automatically create data access set for each one of them as highlighted above. Now let assume that we have 10 balancing segments and we don’t want to give access of all the balancing segments to the user. We want to restrict the access of a particular balancing segment to a particular user. Let say we want to create a data access set for 03 balancing segment. For that click on create
Select the COA and accounting calendar for the ledger. We need to select access type as “Primary Balancing Segment Values” since the system has already created the access for full ledger as already discussed.
Select the ledger and uncheck the All values because we are creating the data access set for single 03 value.
Select Specific values as Single value because if we select parent value it will have access to the parent value as well as all the child values under the parent value
Select the Segment value and the privilege which we want to give it to the user. Click on Save and Close.
Comments
Thanks for this article. It is very beautifully explained.
I have a small doubt : in the above article i have read - User must have an access to the segment values associated with the data access sets to access the corresponding GL account. Is this security rules or is it anything different. Kindly explain.
Thanks for this article. It is very beautifully explained.
I have a small doubt : in the above article i have read - User must have an access to the segment values associated with the data access sets to access the corresponding GL account. Is this security rules or is it anything different. Kindly explain.
Thanks for this article. It is very beautifully explained.
I have a small doubt : in the above article i have read - User must have an access to the segment values associated with the data access sets to access the corresponding GL account. Is this security rules or is it anything different. Kindly explain.
Thanks & regards
mohan
RSS feed for comments to this post