As in most software packages, you can assign user rights in Lucanet in a very granular way. Although many customers simply check the “all rights” box for new users out of convenience, this is certainly not a best practice. Doing so allows anyone, for example, to move accounts, delete imports or open and close periods. In this blog post we will give you some tips on how to properly manage your Lucanet user rights.
Assigning individual rights per user is not necessary in Lucanet. In fact, it is easier to use user groups for this purpose. First you configure the rights, then you assign users to the user group. In addition, users can belong to multiple user groups.
Within our implementations, we always create two types of user groups:
We then link the users to two user groups. This way you maintain a clear overview of access to your organization’s financial data and you never have to assign additional individual user rights.
Think carefully about whether users should be able to create elements. A good example is the intercompany partner dimension. Normally something is only added here when a new company is created. In most cases users do not need write access to this dimension. They can simply assign imports to an existing element while having only read access to the dimension.
If all your users are on the same authentication platform, it is always advisable to integrate Lucanet with it. This means users do not have to remember separate passwords, and IT can easily disable access when employees leave the company. This can be done using Microsoft Entra ID or Okta via OIDC or SAML. You can even go one step further by implementing SCIM.
It is easy to check in Lucanet when users last logged in. This helps prevent user licenses from being underutilized:
You can also easily export an overview of the configured user rights. These reports can be useful for documenting changes in user rights and are often helpful during audits:
Can’t see the effective rights anymore because of all the check marks? Contact us today!