Skip to main content
Share / Export

Setting Up VA Attachment Type Security

VA Attachment Type Security sets who can open secured attachment types (examples: HR Drug Test Results, HR Employment App). Trimble procedure title: Set Security for Attachment Types.

Attachment-type security works only after four pieces are in place (Enable Attachment Type Security): (1) secure the types, (2) set up security groups, (3) set up form security, (4) grant access by type to users and/or groups.

Before you start​

  • Assign security before users get system access when possible.
  • In DM Attachment Types, check Secured for types to protect. The grid here shows only Secured = Y types (confirm with F4).
  • Security groups used here must be Group Type = Attachment Type on VA Security Groups.
  • You need form-security permission to administer attachment type security for the companies you select.

Steps​

  1. Confirm Secured on the types in DM Attachment Types.
  2. Open VA Attachment Type Security.
  3. Attachment Type: enter / F4, or leave blank for all secured types.
  4. Company: Select Company (then enter company or F4), or Across All Companies / Across Companies I have permissions for (label depends on your form-security scope).
  5. Group/User: Security Group or User. Enter a specific value or leave blank for all groups / all users.
  6. Click Refresh. Grid shows matching secured types only.
  7. Set access:
    • Per row Access dropdown: Allowed (grant) or None (no specific access; often used at user level to defer to the group). There is no Denied level.
    • Or Initialize Access Level → Initialize Security Access → pick Access Level → Apply (sets every grid row).
  8. Click Apply. Success message may say “query security” updated (wording mismatch; this form is attachment-type security).
  9. To override a group member: filter to that User and set Allowed/None again.

Hard rules​

  • Attachment-type access alone is not enough. The user must also have permission to view the record on the form (VA Form Security). Example: AP attachment on AP Vendors is still blocked without AP Vendors form access.
  • Default secured types for audit attachments: HQ Batch Control audits use HQ Sensitive; PR Ledger Update audits use PR Sensitive. Users who need those reports must be granted those types.
  • Prefer groups, then user-level overrides. Enable page says attachment type security generally is not applied to specific users; procedure/form still allow user customization.
  • Restrict PR/HR types tightly.

Notes​

  • Related: DM Attachment Types; Initialize Security Access; VA Security Groups; VA User Profile; VA Form Security; Attachment Form / DM Standalone Documents; DM Manage Attachments; About the HQ Batch Control Form; Set Up Attachment Types; About the Interaction Between Group and User Level Security Settings.