Setting Up VA Security Groups
VA Security Groups creates groups and adds users so you can administer permissions for many users instead of one at a time. Each group has one Group Type that limits which security area it covers. After the group exists, set permissions on the matching security form. The form also pushes security to SSRS Report Servers configured on RP RS Server. Trimble procedure title: Create Security Groups.
Group security is recommended; user-level overrides are allowed; user-only security without groups is also allowed.
Before you start
- To add or delete group members you need: form security to VA Security Groups; form security to every company where that group is used; access to every other security type where the group is used (Forms, Reports, Inquiries, Work Center, or Attachment Types).
- Recommended: a group named Standard Viewpoint Forms with access to VP forms (forms not tied to a form or module, for example Batch Selection, Field Properties). Associate all users with that group in all companies.
- Decide how many typed groups each role needs (wider access means multiple groups).
Steps
- Open VA Security Groups.
- Security Group: unique number (up to 7 characters). F4 lists existing groups.
- Name: up to 30 characters.
- Group Type (dropdown). Field defs: 0-Data, 1-Program, 2-Reports, 3-Attachment Type. (The form page sometimes says “Form” instead of Program; Create Security Groups matches Program.)
- Description optional (up to 256 characters).
- Assign users:
- First implementation: Users tab → User Name (type or F4). Saving updates VA User Profile (and the reverse is also true).
- After implementation: prefer adding the user in VA User Profile after the login is created.
- Bulk: VA Add Users to Group.
- Save.
Then set permissions on the matching form: VA Form Security (Program), VA Report Security (Reports), VA Attachment Type Security (Attachment Type), and VA Data Security Setup / VA Data Security Access (Data).
Delete a group
Remove all users first or delete is blocked. Use Delete or Edit > Delete. Installed Group 0 (Default Security) cannot be deleted.
Hard rules
- Group 0 (Default Security) is automatically granted access to any new datatype marked secured. Every other user and group must be granted that access separately.
- Group Type can be changed only if the group has no entries in VA Form Security (including tab security), VA Data Security Access, and VA Report Security. (Form purpose text also names VA Data Security Setup and VA Attachment Type Security; the change-block note uses Access and omits Attachment Type.)
- Any add, change, or delete writes an HQMA audit row (view on HQ Audit Detail).
- Multi-group: the least restrictive group setting wins. User-level settings interact with group settings (see Interaction Between Group and User Level Security Settings).
- Prefer groups first, then individual overrides.
Notes
- Related: Create Security Groups; Add Users to Security Groups; VA User Profile; VA Add Users to Group; Assign User Security; VA Data Security Setup / Access; VA Form Security; VA Report Security; VA Attachment Type Security; RP RS Server; SSRS Security Overview.
- Field defs Name text may say the name identifies the “report” group even on this general security-group form.