Restricting Access to Sensitive Documents in Microix

Creation date: 8/27/2026 2:00 PM    Updated: 8/27/2026 2:19 PM   documents restricted sensitive

Overview

Microix can be configured to restrict access to sensitive documents so that only authorized users can view, approve, search, or report on those transactions.

For example, if payroll journal entries are created or imported into Microix, you may want only designated users, such as Payroll staff and the CFO, to have access to the transactions and their supporting documentation. Other users should not be able to locate the documents through Document Search, Approve Documents, reports, or other areas of the system.

The recommended approach is to use dedicated workflow(s) for sensitive documents and carefully control both workflow membership and administrative permissions.

1. Identify the Restricted Workflow(s)

Identify or create one or more workflows that will be used exclusively for sensitive transactions.

Examples may include:

  • Payroll Journal Entries
  • Executive Transactions
  • Confidential AP Transactions
  • Other transactions containing sensitive financial or personnel information

Only users who are authorized to access these documents should be assigned to these workflows as Requesters or Approvers.

Review each restricted workflow and verify that no unauthorized users are included at any workflow level.

Important: Workflow membership determines who normally participates in and has access to documents within the workflow. A restricted workflow should not be shared with users who should not have access to its documents.

2. Remove Permissions That Can Bypass the Restrictions

For users who should not have unrestricted access to sensitive documents, remove permissions that could allow them to bypass the workflow restrictions or modify the configuration.

Remove for all users except unrestricting ones:

Button/Function

  • Show All Documents
  • Login As
Menu Items:
  • Maintenance>User Maintenance
  • Maintenance>Security
  • Maintenance>Organization Workflow
  • Maintenance>System Audit
  • Support>Database Query
  • Reporting>Download Documents

These permissions should only be assigned to trusted administrative users who are authorized to have unrestricted access to documents throughout the system.

3. Review Display Account Balance Access

If users have access to Display Account Balance, additional restrictions may be necessary when sensitive transactions are posted to specific GL accounts, funds, departments, or other accounting segments.

Review workflow Account Restrictions to determine whether detailed account activity associated with sensitive transactions should be visible.

Where necessary, restrict the appropriate accounting codes that unauthorized users cannot drill into detailed activity for sensitive accounts.

Another option is to use Global Setting 304 "Hide detailed information when viewing Account Balance (Enter each GL code separated by commas)" To add any GL account codes that potentially can be seen by an unauthorized users via the display account balance page when using the drill down feature.

4. Process Sensitive Documents Through the Restricted Workflow

After the security configuration is complete, ensure that all sensitive documents are created or imported using one of the designated restricted workflows.

The workflow assignment is critical. If a sensitive document is created using a general workflow, users assigned to that workflow may be able to access the document.

For imported transactions, verify that the import process assigns the correct restricted workflow before placing the process into production.

5. Test the Configuration

After completing the setup, test the security configuration before processing sensitive production documents.

Using an authorized administrator account with the Login As function:

  1. Log in as a typical user who should not have access to the restricted documents.
  2. Open Document Search and verify that documents assigned to the restricted workflow cannot be located.
  3. Open Approve Documents and verify that restricted documents are not available.
  4. Run applicable reports and verify that the user cannot retrieve documents from the restricted workflow.
  5. Review Display Account Balance, if applicable, and verify that sensitive detailed account activity is not accessible.
  6. Verify that the user cannot access functions that would allow them to change workflow or security settings.
  7. Repeat the test with representative users or security roles as necessary.

Recommended Security Practice

Access to sensitive documents should be controlled using multiple layers:

Restricted Workflow + Restricted Workflow Membership + Removal of Administrative/Bypass Permissions + Account Restrictions (when applicable)

Periodically review workflow membership and security permissions to ensure that only authorized users continue to have access to sensitive documents.