Permissions Audit Capability or Report? Permissions definitions?
We have just gone into our second year using CSuite and are ready to take a hard look at Permissions. We are finding we would rather have 'departmental' user groups than just the default distinction between Accounting and Staff that was set up at implementation. We have just been granting specific permissions on the fly, as staff run into tasks they are unable to complete, and would like to re-establish a controlled structure.
We are running into a few hurdles as we try to approach this project, specifically:
1: there aren't any good definitions on WHAT each permission actually does ( for example, what is the difference between 'display' and 'list'?)
2: there doesn't seem to be any efficient way to get an audit report to see what the current settings ARE for each group. As it stands you have to manually go into each 'Object' (such as Accounts, Bank Reconcile, Funds) and then click 'Show Advanced' to see the detailed settings. Then once you're able to SEE them, there is no good way to export that information so you can get it into a meaningful format.
I was able to do a bulk granting of permissions to a test group, then used an Audit Log report to see what actions were taken by the system, and was able to extrapolate that there are over 600 specific permissions. I've attached the resulting spreadsheet here, perhaps it will save someone else the time.
It really would be very helpful if the UI for managing permissions could be built out to help administrators review, audit and issue permissions more intentionally.
Here is a link to a help article which lists the description of each permission:
https://support.foundant.com/hc/en-us/articles/4447782019351-Detailed-Permissions
There are several custom reports that should help you review the permission settings in your site.
- Group - will give you a list of groups
- Group Action - will give you a list groups along with the advanced action for each group. The report can be grouped by the object, then sorted by the group name to review a site's permissions
- User Action - will give you a list of Users and the permissions that they have access to. The report can be grouped by employee then sorted by object.
- User Group - will give you a list of employees and the group they have been assigned to. The report can be grouped by group name to easily review the users assigned to each group.
-
Meghan Warrick commented
Completely agree! Great suggestion.
-
Susan Lotreck commented
Thank you for so perfectly describing what is needed with regards to permissions in CSuite. We are babies in CSuite- live as of July 25, 2022 and I know our auditors are going to want to see user permissions on a detailed level with descriptions. I appreciate you sharing your work around.
-
Amy Lemmons commented
permissions are very overwhelming but so important. Thank you for making this suggestion!