You are on page 1of 19

Module 7: Controlling Access to Customer Data

Module Objectives
After completing this module you will be able to: Describe the different Access Control mechanisms used to restrict access to data in Siebel eBusiness Applications Identify the different view types used to accommodate different types of users

Why you need to know: To effectively use Siebel eBusiness Applications, you need to understand how access to data is controlled

Business Challenge
Users often perform the same job functions but on different sets of data For example, sales representatives need access to the records for their own accounts, but not each others Access to some data in the enterprise needs to be restricted Users should only see records they need to do their job Users should easily locate records of interest

Database

Accounts

Accounts

Solution
The method of data Access Control for each user is managed through Position, Organization, and User ID

Organization

Position

Records

User

User ID

Is assigned to

Provides access to
4

Relationship Between Views and Data


Access to views is independent of access to data But the view defines the Access Control mechanism that will be used to access data Data displayed within a view is based on the Access Control mechanism for the view Example: Ted Arnold and Casey Cheng can access the same view based on their responsibilities, but see different data in the view

My View
Displays records directly assigned to you based on user ID or active position

A sales agent only sees accounts for which one is on the account team

My Personal View
Is used to display records that you directly own Is a special-case view that is rarely used (for example, with Contacts)

A sales agent only sees contacts for which she is the direct owner

My Teams View
Is an additional view for managers that allows them to see records assigned to their direct and indirect reports

For records with teams of positions, only the primary is displayed Manager does not have to be assigned to the record
Is typically assigned only to the manager responsibility

Manager sees only the accounts for which managers direct/indirect reports are the primary position on the account
8

All View
Is used to access all records associated with the users organization

A valid owner must be assigned to the record


Is typically restricted to users who need to access records at the organization level

Executives Administrators Service agents who need to access all service requests

A service agent sees all the service requests assigned to his organization

All Across My Organizations View


Is used to access all records in the enterprise that are assigned to the users organization and its child organizations A valid owner must be assigned to the record Is typically restricted to users who need to access records at the enterprise level Mid-level executives Partners Is typically used for only a few types of records In the All Opportunities Across My Organizations view, a sales manager sees all opportunities in his organization and all of its child organizations

10

All Across Organizations View


Is used to access all records in the enterprise

A valid owner must be assigned to the record


Is typically restricted to users who need to access records at the enterprise level

Top-level executives Administrators

A vice president of sales can see all accounts that have been assigned

11

Administration Views
Display all database records, even those without a valid owner Such as records that have just been imported but not yet assigned Accessed from the Administration views for each major entity Site Map > Administration - <entity> Site Map > <entity> Administration Should be restricted to a few users in the enterprise as they display all records in the database

Administration views in Site Maponly a few shown

12

Summary: Types of Views


Views My View My Personal View My Teams View (Managers View) Description Displays records directly assigned to you based on user ID or active position Only displays records you directly own Allows managers to see records assigned to their direct and indirect reports that are the primary owner based on reporting structure Displays all records associated with the users organization Displays records that are assigned to the users organization and its child organizations Displays all records in the enterprise with a valid owner Display all records in the database, even those without a valid owner

All View All Across My Organizations View All Across Organizations View

Administration Views

13

Access to Customer Data


Can be restricted by assigning individual records to: Users Positions Organizations

14

Team Access Control


Represented using a MVG Position field One position on the team is designated as the primary (by default, this is the creators active position) Fields vary according to the view in which they appear Examples: Opportunity form has a Sales Team field Team fields often show User ID for a position assigned to the team

Account form has an Account Team field

Contact form has an Contact Team field

15

Using Multiple Access Control Mechanisms


A record can be restricted by more than one Access Control mechanism - Mechanisms are not mutually exclusive A view is preconfigured to use only one mechanism at a time - If you want to use another mechanism, you create and configure another view

16

Examples
A users position may be assigned to an account that is not assigned to that users organization - User sees the account in the My View - User does not see the account in the All View

Contacts have multiple access mechanisms: public (team-based), private (positionor user IDbased), and manager - User sees public contacts in the My View - User sees private contacts in the My Personal View - Manager sees contacts for self and subordinates in the My Teams View

17

Summary of Record Assignment


Standard Siebel business entities can be assigned to single or multiple users, positions, or organizations Single-Valued Access Service requests Expense reports Contacts Forecasts Quotes Assets Consumers Forecasts

Access Method

Multi-Valued Access

Users

Assets Activities Accounts Contacts Opportunities Accounts Opportunities Quotes

Positions

Team Access Control

Organizations

18

Summary
This module showed you how to: Describe the different Access Control mechanisms used to restrict access to data in Siebel eBusiness Applications Identify the different view types used to accommodate different types of users

19

You might also like