Setting Up VA Data Security
VA Data Security Setup turns on row-level data security (companies, employees, jobs, contracts). VA Data Security Access then grants security groups access to those values.
Before you start
- Enable security administration in VA Site Settings.
- Create data security groups (default all-companies group plus company-specific groups as needed).
Steps — activate data security
- Open VA Data Security Setup.
- Activate the data types you need (for example BHQCO for company numbers).
- Assign a default security group (for example 10000) for all existing and future companies when appropriate.
- For granular company access, use one security group per company and assign users accordingly.
- For employee data, use default group 9999 and manage membership through payroll groups—do not add users directly to 9999.
- For jobs/contracts, set security groups on the JC job and JC contract forms as required.
Steps — grant access
- Open VA Data Security Access.
- Select the data type (for example BHQCO).
- Click Refresh.
- Sort by security group to review current access.
- Check Allow access for each security group / value combination that should see the data.
- Click Apply.
Notes
- Prefer global/group security over user-level data security.
- Never put users directly in the employee default group 9999.