Acubiz uses an enhanced security layer for managing user master data. This control measure supports the principle of segregation of duties (four-eyes principle) and ensures that employees operate only within their assigned areas of responsibility.
As an administrator in Acubiz, the following two main rules apply for user administration:
1. Restriction on Self-Editing
⚠️ For security reasons, an administrator cannot edit their own user profile.
- Standard procedure: Changes to your own profile must be made by a colleague with administrator rights.
- If you are the sole administrator: If the company has no other administrators, changes can be made by Acubiz Support. Please note that this is a billable service.
2. Access Restriction Across Companies
An administrator can only create and edit users in the companies to which they have explicit access. Access control is based on two fields in the administrator’s profile:
- Primary company: Automatically grants access to manage users in the administrator’s own primary company.
- Secondary companies: Must be explicitly filled out if the administrator is to have rights to manage users in other companies within the group.
ℹ️ Read more: Extend a user’s roles to secondary companies
Example
An organization consists of 7 companies. An administrator is assigned access to Denmark (primary company) and Sweden (secondary company).
The administrator can see all users in the overview but can only edit users in the companies to which access has been granted:
- ✅ Denmark (Access to edit)
- ✅ Sweden (Access to edit)
- 🛑 Norway (No access)
- 🛑 Germany (No access)
- 🛑 Finland (No access)
- 🛑 Austria (No access)
- 🛑 United Kingdom (No access)
Administrator’s setup:
User overview:
If the administrator attempts to edit a user in a company without assigned access (e.g., Norway), the system will reject the action with the following error message:
Comments
0 comments
Please sign in to leave a comment.