Configuring Access Controls for different Data Security Context
We know that it's a risk if an user has access to Invoice creation and payment creation role. But it's a violation if the user has data security access to the same Business Units. If the user has Invoice Creation Role for BU1 (data security access to BU1) and Payment Creation Role for BU2 (data security access to BU2) - it should not be flagged as a risk. How to configure data security sensitive access controls? Can the Perspective or Global Conditions be used to achieve this?
Any other ideas is also welcome.
0