Effective management of user rights in Lucanet

As in most software packages, you can assign user rights in Lucanet in a very granular way. Although many customers simply check the “all rights” box for new users out of convenience, this is certainly not a best practice. Doing so allows anyone, for example, to move accounts, delete imports or open and close periods. In this blog post we will give you some tips on how to properly manage your Lucanet user rights.

Make use of user groups

Assigning individual rights per user is not necessary in Lucanet. In fact, it is easier to use user groups for this purpose. First you configure the rights, then you assign users to the user group. In addition, users can belong to multiple user groups.

Within our implementations, we always create two types of user groups:

  1. For the function (e.g. controllers, management, etc.). In this user group we assign most functional rights: on worksheets (whether the group can read the P&L or also change the structure), on data dimensions, partners, valuation dimensions, etc.
  2. For access to specific companies. In this user group only rights are configured for viewing or editing data for specific entities.

 

We then link the users to two user groups. This way you maintain a clear overview of access to your organization’s financial data and you never have to assign additional individual user rights.

 

Don’t automatically give rights to create elements

Think carefully about whether users should be able to create elements. A good example is the intercompany partner dimension. Normally something is only added here when a new company is created. In most cases users do not need write access to this dimension. They can simply assign imports to an existing element while having only read access to the dimension.

Login with external authentication

If all your users are on the same authentication platform, it is always advisable to integrate Lucanet with it. This means users do not have to remember separate passwords, and IT can easily disable access when employees leave the company. This can be done using Microsoft Entra ID or Okta via OIDC or SAML. You can even go one step further by implementing SCIM.

Check usage

It is easy to check in Lucanet when users last logged in. This helps prevent user licenses from being underutilized:

 

 

You can also easily export an overview of the configured user rights. These reports can be useful for documenting changes in user rights and are often helpful during audits:

 

Can’t see the effective rights anymore because of all the check marks? Contact us today!

Schedule an appointment

Looking for a simple and straightforward solution for finance tooling?