Manage security for dimension hierarchies

As of Planning Analytics 2.0.9.5, you must assign security for dimension hierarchies independent of the parent dimension. Hierarchies do not inherit security from the parent dimension. If you do not explicitly set security for an hierarchy, the default security is NONE.

About this task

Hierarchy security must be defined in the }DimensionSecurity control cube. Hierarchies are not exposed in the dimension settings editor.

The following rules apply to security on hierarchies.
  • The hierarchy with the same name as the dimension shares the same security as the parent dimension. The same named hierarchy cannot have a different security level than the dimension.
  • A user group cannot have higher security access to an hierarchy than to the parent dimension.
  • Any security applied to the Leaves hierarchy is ignored. If a user has READ privilege on the parent dimension they will also have READ privilege to the Leaves hierarchy. The Leaves hierarchy is automatically updated to include all leaf members of all hierarchies in a dimension.
  • READ privilege or higher is required to see both the subsets and members in a hierarchy.
  • LOCK and RESERVE privilege are not applicable to hierarchies.

Procedure

  1. Open the }DimensionSecurity control cube.

    The control cube contains two control dimensions, }Dimensions and }Groups.

    Hierarchies are prefixed with the parent dimension name, dimension_name:hierarchy_name. In this example, model:CustomerTarget, model:Drive, model:EngineSize and others are hierarchies of the model dimension.

  2. Enter the desired security privilege at the intersection of an hierarchy and a user group. Security privileges for user groups are described in Assigning Security Rights to Groups.

    For example, here the South America user group has READ access to the model:CustomerTarget and model:EngineType hierarchies.

    Hierarchy security definitions 2.0.9.5 and later