Microix can be configured to restrict access to sensitive documents so that only authorized users can view, approve, search, or report on those transactions.
For example, if payroll journal entries are created or imported into Microix, you may want only designated users, such as Payroll staff and the CFO, to have access to the transactions and their supporting documentation. Other users should not be able to locate the documents through Document Search, Approve Documents, reports, or other areas of the system.
The recommended approach is to use dedicated workflow(s) for sensitive documents and carefully control both workflow membership and administrative permissions.
Identify or create one or more workflows that will be used exclusively for sensitive transactions.
Examples may include:
Only users who are authorized to access these documents should be assigned to these workflows as Requesters or Approvers.
Review each restricted workflow and verify that no unauthorized users are included at any workflow level.
Important: Workflow membership determines who normally participates in and has access to documents within the workflow. A restricted workflow should not be shared with users who should not have access to its documents.
For users who should not have unrestricted access to sensitive documents, remove permissions that could allow them to bypass the workflow restrictions or modify the configuration.
Remove for all users except unrestricting ones:
Button/Function
These permissions should only be assigned to trusted administrative users who are authorized to have unrestricted access to documents throughout the system.
If users have access to Display Account Balance, additional restrictions may be necessary when sensitive transactions are posted to specific GL accounts, funds, departments, or other accounting segments.
Review workflow Account Restrictions to determine whether detailed account activity associated with sensitive transactions should be visible.
Where necessary, restrict the appropriate accounting codes that unauthorized users cannot drill into detailed activity for sensitive accounts.
Another option is to use Global Setting 304 "Hide detailed information when viewing Account Balance (Enter each GL code separated by commas)" To add any GL account codes that potentially can be seen by an unauthorized users via the display account balance page when using the drill down feature.
After the security configuration is complete, ensure that all sensitive documents are created or imported using one of the designated restricted workflows.
The workflow assignment is critical. If a sensitive document is created using a general workflow, users assigned to that workflow may be able to access the document.
For imported transactions, verify that the import process assigns the correct restricted workflow before placing the process into production.
After completing the setup, test the security configuration before processing sensitive production documents.
Using an authorized administrator account with the Login As function:
Access to sensitive documents should be controlled using multiple layers:
Restricted Workflow + Restricted Workflow Membership + Removal of Administrative/Bypass Permissions + Account Restrictions (when applicable)
Periodically review workflow membership and security permissions to ensure that only authorized users continue to have access to sensitive documents.