Revised: 10/10/2022


Maintaining OAKS FIN User Security Roles

It is the responsibility of the CFO or agency FIN Security Designee to review existing security roles, add new or update existing roles, delete old roles, and ensure that users of OAKS FIN have the access they need to do their jobs and no more access than they need.

 

Sections in this topic HideSections in this topic Show
  1. Reviewing Security Roles for OAKS FIN Users
  2. Accessing the Online Security Request
    1. Review Current Access
    2. Add or Update Security Access
    3. View All Previous Requests
    4. Delete All Access
    5. Recent OAKS FIN Role Additions

 

Reviewing Security Roles for OAKS FIN Users

 

 

Prior to accessing the Online Security Request, review the information contained in the Agency FIN Role Handbook available in OAKS FIN using the OH_ROLE_HANDBOOK query.

  1. Choose "Query Name" in the Search By dropdown box.
  2. Enter "OH_ROLE_HANDBOOK" in the begins with field.
  3. Click Search.
  4. Select Run to format from Query.

 

 

 

Accessing the Online Security Request

 

The process of maintaining OAKS FIN security roles is done using the Online Security Request form located in the OAKS FIN application.

 

 

 

  1. Select an Action radio button to:
  2. Enter the Employee Identification Number (EmplID) or use the look up icon to verify or find the Employee ID.
  1. Press Enter on the keyboard.

 

Review Current Access

No changes can be made in the Review Current Access mode. Select the Add or Update Access radio button on the screen if information currently displayed for the user needs to be modified,

 

 

 

Add or Update Security Access

Employee Information, Ledger Group, and Business Unit Access appear at the top of the page. Below that, all the security roles a user already has assigned will appear at the top of a list and all additional roles available appear at the bottom of that list. Access Group, Voucher Processor Origin and Purchasing Workflow information appear at the page bottom when applicable.

 

 

  1. Return to the top of the page.
  2. Select Add or Update Access as the Action.
  3. Verify the Employee Information populated is accurate. If there are errors, contact the agency HR department to update.
  4. Enter a statement in the Requestor field for record maintenance, and when applicable, add an explanation for the request when Central Approval is required.
  5. For Ledger Group, choose one:
  6. Enter the Primary agency Business Unit code for a new user. Verify the Default Business Unit appears when updating roles.
  7. Click the Look up icon to confirm the Default Business Unit code.
  1. Select Specific BUs and click the plus sign (+) if additional Business Units need to be added.

  1. Click in the appropriate Add Role or Delete Role box to make adjustments.
  1. Choose an Access Group name to determine the time of day OAKS FIN will be available to the user.
  2. Click the Submit Request button.
  1. Only the roles added or deleted will appear for review.
  1. After review, click either the Finalize Request button to submit, or Modify Request button to make adjustments.
  1. Depending on the access requested, a warning may appear stating that the request has to be approved at the central level.  Email notification is sent to the requester once the request has been approved and processed or when it is denied.

 

If central approval is not required, the request will be processed and access will be immediately available to the employee. (Some agencies have additional internal requirements.)

 

View All Previous Requests

Updates made for the user since online security go-live date will appear along with any comments.

 

  1. At the top of the page select View All Previous Requests as the Action.
  2. Enter the Employee Identification Number (EmplID).
  3. Press Enter on the keyboard.
  4. Approval information shows when the request was submitted, if status update has been granted or pending approval, who submitted the request, whether or not Central Approval was required, who approved the request, and when it was approved.
  5. Comments from the requester and approver will appear if entered.

 

  1. Click the View All link at the top of the page to review multiple updates (three per page).

Or

Click the forward or backward icon to view updates one at a time.

 

Delete All Access

All roles currently assigned to a FIN user are marked for deletion when submitted. Once finalized, roles will be deleted immediately and cannot be undone.

 

  1. Select Delete All Access as the Action.
  2. Enter the Employee Identification Number (EmplID).
  3. Click Enter.

Or

Use the look up icon to find the ID.

  1. Optional: Click the Previous Request Comments link to view prior requests for security updates for the user along with any comments.

 

 

  1. Click OK to close.
  2. View the Prior Request Status of a request that has not been processed and any related comments from the requestor.

 

 

To remove all non-workflow related roles, choose the Add or Update Access mode to delete only select roles. Once the workflow team cleans up the remaining issues the Agency Security Designee can go back into Delete All Access mode to finish removing that user’s remaining access.

 

Contact the OAKS FIN Helpdesk at OAKS.Helpdesk@oaks.state.oh.us to create a ticket for the PO-RACM Purchasing Team when there are outstanding worklist items and have them appropriately transferred, closed, deleted, etc.

 

  1. Click the Submit Request button at the bottom of the page.
  2. A warning message appears asking the submitter to review the request and verify that they truly want the individual to have their access fully revoked.
  1. Click the OK button to confirm the request.
  2. Click the Finalize Request button to revoke all access for the employee.

Or

Click the Modify Request button to make changes.

  1. A message will appear stating the request to delete all FIN access is approved and granted.  
  1. Click OK.

 

Recent OAKS FIN Role Additions

Details on OAKS FIN security roles that were effective September 2015 are shown below. It will help in selecting the appropriate role for a user when they request access to OAKS FIN. The tables below will list any required information when completing the Online Security Request that must be provided by the OAKS FIN Security Designee when requesting the role.

 

Accounts Payable (AP)

Role

Description

Additional Information for Security Designee

OH_AP_VCHR_SU – AP Voucher
Spreadsheet Upload
Grants access to agency users to upload vouchers offline into OAKS FIN. Creates vouchers from the upload during the nightly batch voucher build process.
Requires Central Agency approval
OH_LOCATION_FORM_REQUESTOR – Location Requester Grants access to the Location request forms - Users will be able to submit requests to add and/or update locations.    

N/A

OH_PCARD_FORM_REQUESTOR – Pcard Requester Grants access to the Pcard request form. This role is only given to the CFO, the Agency payment card administrator or their documented designee to submit a form through OAKS FIN to update agency payment cardholder information.      

N/A

Accounts Receivable (AR)

Role

Description

Additional Information for Security Designee

OH_AR_CUST_TYPE_MAINT – Customer Type Maintainers Grants access to maintain the customer types.   Requires Central Agency approval.
OH_ISTV_ADMIN – ISTV Administrator Grants access to create ISTV reports and delete ISTV vouchers.   Requires Central Agency approval.
OH_ISTV_VIEWER – ISTV Viewer Grants access to the ISTV Viewer page to see both the AP and AR sides of the transaction, including attachments. Users who process, maintain or pay ISTVs should be granted access to this page. These are usually the AP voucher processors and maintainers.  

 

 

N/A

Billing

Role

Description

Additional Information for Security Designee

OH_BI_UPLD_SU – Billing Spreadsheet Upload Grants access to submit transactions via the Billing Spreadsheet.   Requires Central Agency approval.

BPM

Role

Description

Additional Information for Security Designee

OH_EPM_BP_AGY_REPORTING - EPM Agency Budget Reporting     Requires Central Agency approval
OH_EPM_BP_PREPARER - EPM BP Preparer     Requires Central Agency approval   When the EPM BP Preparer role is assigned:
  • The BPM Access - Agency Access Only section will display with the corresponding radio button selected.
  • The Agency Budgets & Planning section will display with the Expenses Planning Centers, Revenues/Transfers Planning Centers, and Capital Planning Centers.
  • All Planning Centers that the user has access to (as defined by the user's Business Units assigned) will automatically populate.
  • The Security Designee has the option of deleting specific planning centers that the user should not have access to.
OH_EPM_BP_REVIEWER - EPM BP Reviewer     Requires Central Agency approval   When the EPM BP Reviewer role is assigned:
  • The BPM Access - Agency Access Only section will display with the corresponding radio button selected.
  • The Agency Budgets & Planning section will display with the Expenses Planning Centers and Revenues/Transfers Planning Centers.
  • All Planning Centers that the user has access to (as defined by the user's Business Units assigned) will automatically populate.
  • The Security Designee has the option of deleting specific planning centers that the user should not have access to.
  • Note that there is not a reviewer section for Capital Planning Centers as agency users do not have that access available.

eSettlements

Role

Description

Additional Information for Security Designee

OH_ESET_SUP_W_SEC – eSettlements Supplier with security functions for company Grants access to the supplier to perform eSettlements related tasks. It will also allow this user to perform security related tasks for their company, including additional user access and password resets.   Requires Central Agency approval.
OH_ESET_SUP – eSettlements Supplier with no security functions for company Grants access to the supplier to perform eSettlements related tasks.   Requires Central Agency approval.
OH_ESET_BUYER – eSettlements Agency Buyer Grants access to eSettlements for agencies. This allows agencies to view their details, agreements and verify invoices.  
  • Business Unit
  • Origin
OH_ESET_BUYER_VIEW_ONLY – eSettlements Agency Buyer view only Grants view only access to eSettlements for agencies.
  • Business Unit
  • Origin

eSupplier

Role

Description

Additional Information for Security Designee

OH_ES_VENDOR_USER_ADMIN – eSupplier Supplier with security functions for company

Grants access to the supplier to perform eSupplier related tasks. It also allows the user to perform security related tasks for their company, including additional user access and password resets.

 

 

 

N/A

OH_ES_VENDOR_USER_VIEWER – eSupplier Supplier View Only Grants view only access to eSupplier for the supplier.  

N/A

OH_ES_VENDOR_USER – eSupplier Supplier with no security functions for company   Grants access to the supplier to perform eSupplier related tasks.

 

N/A

Expenses (EX)

Role

Description

Additional Information for Security Designee

OH_EX_NON_TRVL_APPROVER – Non Travel Expense Approver Grants access to approve the expense report after the HCM assigned supervisor has approved non-travel expenses only. This access allows changing the ChartFields on the expense report. Department ID or a range of Department IDs is required.

General Ledger (GL)

Role

Description

Additional Information for Security Designee

OH_GL_AGY_COA_REQUESTOR – Agency ChartField Requester Grants access to the ChartField request forms. The user can create and submit requests to add a new ChartField or request an update to an existing value.  

Assign one of these two ChartField roles to the same user (i.e., do not assign the Requestor AND the Approver role to the same user). The Approver role will allow the user to request and approve.

  • When the Agency ChartField Approver  role is assigned, the GL AGY COA APP Group Box section will display.
    • The Route Control Profile section defines the routing for Chartfield request workflow.
    • Select the agencies the COA Approver  will review and approve ChartField requests for.
OH_GL_AGY_COA_APPROVER – Agency ChartField Approver Grants access to approve the ChartField request forms.
OH_GL_DEPTID_UPD_NOTIFY – Department ID Updates Notification Grants view only access to the Department ChartField request form. Users in GL, EX and AM will be notified when a new DEPTID is added.    

N/A

 
OH_GL_CNTR_BUDGET_ANALYST – Central Budget Analyst Grants access to review and post Allotment budgets for designated agencies.  This role will also delete budget entries directly in OAKS FIN or through a batch upload process.  A person in this role can override budget limits for Allotment.  This role can also update agency budget as needed to assist the agencies.  

In the Route Control Profile section, select the agencies the Budget Analyst will review and post Allotment budgets for.

Purchasing (PO)

Role

Description

Additional Information for Security Designee

OH_PO_NOVICE_REQUESTOR – Novice Requester Grants access to create a requisition using minimal information.
  • P location (shipping location)
  • Department
  • ALI
  • Fund Code
  • Account
  • Program Code

 

  • Cannot assign role to a user with the Requestor or Requisitioner role.

 

 


Click here to request updates to this topic.