Security Restrictions and Access to Data

This section describes the effects of applying security restrictions. Using a system of certification of Callista functions, it provides the information required by system administrators to ensure that security restrictions applied to users have a predictable, required effect.

The purpose of this section is:

In this section:

General Considerations

Security restrictions and data access tools

Security restrictions act to limit the 'select' and 'operational' (update, insert, delete) access of users, to particular sets of data. The set of data is the data related to values for which restrictions have been granted. For example, a user may be restricted to data for a particular organisational unit (org unit) or a particular correspondence type.

Security restrictions are applied at the database level, to tables and views. They restrict 'select' and 'operational' access of users accessing data in those tables and views, through forms. Importantly, they also restrict access to data by other means, including by data query tools such as SQL Plus, SQL Navigator and Oracle Browser.

Expected error messages

Users may encounter security restriction related error messages when they execute a query within a form. This may occur when the query returns records containing data drawn from database tables to which a security restriction applies, and that data relates to a security restriction for which the user does not have the appropriate restriction grants.
For example, consider a user with an org unit restriction of 'restricted select' for org unit '04' only. If the user executes a query in CRSF2120 (Maintain Unit Categories) which retrieves a unit category with category member units owned (teaching responsibility org unit) by org units other than '04', the unit codes are displayed but the unit short titles of those units are not. An error message ' Error: This Unit Code, version Number does not exist' is displayed. This occurs because while there is no org unit restriction security over the table containing unit categorisations (UNIT_CATEGORISATION), there is org unit restriction security over the table containing the unit short titles (UNIT_VERSION).

Expected Error Messages

Expected Error Message

Interpretation

 This Course Code, Version Number does not exist

This Unit Code, Version Number does not exist

 This Responsible OU does not exist

 This Responsible OU, Responsible OU Start DT does not exist

 This error displays when records are returned and a component of the record is sourced from a different database table that is affected by the user's security restriction. For example, when navigating to the Course Award Inquiry block of CRSF1190 (Maintain Awards), a query is performed to return all courses associated with a particular award. If any of these courses is 'owned' by an org unit for which the user does not have an org unit restriction, their title will not display. This is because the table from which the course title is sourced (COURSE_VERSION) is affected by org unit restrictions. Wherever possible users should be given 'restricted select' access to all org units they are likely to encounter.

 You have attempted an operation for which you do not have the appropriate privileges. Restricted by Organisational Unit.

 Users with 'restricted select' access only for an org unit restriction may invoke this error whenever they try to update, insert or delete a record related to that org unit. If the user should be able to operate on records for the org unit, their org unit restriction must be updated to include insert, update and delete functions.

 

Users with correctly granted security restrictions and with access to only certified functions will rarely encounter these errors. Users should be educated about when expected error and warning messages will be encountered and either how to interpret those messages or who to contact for assistance.

Dealing with shared ownership

Forms such as CRSF1220 (Maintain Course Ownership) can be used to apportion ownership or responsibility across more than one org unit. A user with the restriction, 'restricted select' for org unit '04' only, can enter this form in the context of a course version record for which 04 is responsible. The course version may be jointly owned by 04 and another org unit. The user can see both owning organisational units because, depending on the context of the data, some forms have had the normal organisational unit security on 'select' operation overridden.

Security restrictions and audit forms

No restriction views have been created on the underlying audit database tables. This means that no audit forms are certified. (Refer to Organisational Unit Restriction Certification) Restricted users should not be granted any audit forms. Granting the Course version audit form (AUDF3126) to a restricted user would allow the user access to all course version data.

Correspondence Type Restrictions

Details regarding the operation of correspondence type restrictions are contained in documentation for the Maintain Correspondence Type Security form (SECF0033).

No functions have been 'certified' for correspondence type restrictions. The section Organisational Unit Restriction Certification details the specifics of org unit restriction certification and these are equally applicable to correspondence type restrictions.

Organisational Unit Restrictions

 Impact of Organisational Unit Restrictions

Users may access organisational unit (org unit) related data in a number of ways, including:

Organisational unit restrictions are used to restrict the select and operation (insert, update, delete) access of users, to data related to specific org units. For example, a faculty officer might be restricted to selecting and updating data for their faculty and its related schools only. In some specific contexts, organisational unit security may have been overridden. For example, in the second dot point above, a user can see course award records for org units for which they have an org unit restriction. The org unit restrictions on the award ownership data in the same form are overridden to allow the user to see award ownership records for org units to which they do not have security access.

The documentation for the Maintain Organisational Unit User Restrictions form (SECF0032) describes this functionality in more detail.

Note: Not all org unit related data is subject to org unit restrictions. Restrictions are applied, at the database level, to individual tables and views. Users are restricted only when using data in these tables/views. Refer to the Security Technical Documentation for further information and a complete list of tables and views to which restrictions apply.

Organisational Unit Restriction Certification

The impacts of org unit restrictions are system wide. To ensure that these impacts are predictable, a system of certification has been introduced to guide Security and subsystem specialists in the application of org unit restrictions to users. The intention is that org unit restrictions should only be applied to users of the certified functions. Application of org unit restrictions to users of non-certified functions may produce the desired effects. It may also produce unpredictable effects and will result in error messages being displayed which may be difficult to interpret outside the documentation for certified functions.

Certification involves analysis of existing interaction between specific functions and org unit restrictions, and design enhancements to ensure that the effects of a restriction are exactly as required. Extensive testing ensures the correct results. Certification is an ongoing process that commenced (Release 2.0) with the Course Structure and Planning and Inquiry subsystems.

 Org Unit Restriction Certified Functions

The following table lists all org unit restriction certified functions as at Release 3.1.2. Presently, this consists of Course Structure and Planning, the Inquiry subsystem and Enrolment forms only.

About this table

Restricted Select column

Entries in the restricted select column indicate whether or not an organisational unit 'select' restriction, applied to a user, affects the user's ability to select data in that form or block. For example, if a user has been granted restricted select access to org unit '04' and to no other org units, 'yes' in the Restricted Select column of this table indicates that the user is restricted to selecting data related to org unit 04 only. Where 'yes' is recorded, the impact of the restriction is noted (in brackets). These impacts are:

Restrictions in LOV column

Entries in this column indicate the name of the field adjacent to an LOV where the records in the LOV are restricted by the user's org unit restricted select grant(s). For example, CRSF1130 has an LOV adjacent to the Course Code field which displays a set of course versions limited by a user's restricted select grants. The Restricted By column indicates which aspect of the LOV data the org unit restriction is acting on.

Restricted By column

Indicates the aspect of the data on which the org unit restriction acts. This may not be in the database table to which the restriction applies, but will be in a closely related table. For example, 'unit attempt - course attempt - course version - responsible org unit' indicates the data element (responsible org unit) which is tested against a user's org unit restriction(s) when unit attempt information is retrieved in INQF1200, and the pathway followed.

Operation Restrictions column

This column contains either 'yes' or 'no', indicating whether or not operation restrictions (insert/update/delete) apply within that form/block to users with org unit operation restrictions. For example, if a user has an 'update' restriction for org unit 04 (but not insert or delete), they will only be able to modify existing records related to org unit 04 and will be unable to insert new records or delete existing records relating to that org unit.

Course Structure and Planning

Form

Block

Restricted Select (impact)

Restrictions in LOV

Restricted by

Operation Restrictions

CRSF1110 Maintain Course Types

 

no

 

 

 no

CRSF1120 Maintain Course Type Groups

 

no

 

 

no

 CRSF1130 Maintain Course Categories

 

Course Category

 no

 

 

 no

Course Categorisation

 no (title will not display for restriction affected courses)

Course Code

course version - responsible OU

 no

CRSF1140 Maintain Fields of Study

 

no

 

 

 no

CRSF1160 Maintain Course Attendance Modes

 

no

 

 

no

CRSF1170 Maintain Attendance Types

 

no

 

 

 no

CRSF1180 Maintain Course Group Types

 

no

 

 

no

 CRSF1190 Maintain Awards

 

Award

no

 

 

no

Course Award Inquiry

no (title will not display for restriction affected courses)

 

course version - responsible OU

no, inquiry only block

 CRSF11A0 Maintain Course Statuses

 

no

 

 

no

 CRSF11B0 Maintain Funding Sources

 

no

 

 

no

CRSF11C0 Maintain Reference Code Types

 

no

 

 

no

CRSF11D0 Maintain Course Groups

 

Course Group

no (Responsible OU description will not display for restriction affected courses)

Responsible OU

course version - responsible OU

no

Course Group Member

no (title will not display for restriction affected courses)

Course Code

course version - responsible OU

no

CRSF11F0 Maintain Course Structure & Planning Note Types

 

no

 

 

no

CRSF1210 Maintain Basic Course Details

 

yes (retrieves only courses for which user has org unit select restriction)

Responsible OU

organisational unit

yes

CRSF1220 Maintain Course Ownership

 

Course Version

this form is always entered in context from CRSF1210 where restricted select applies

 

 

can never operate on the context record

Course Ownership

no (org unit restrictions have been overridden for this block. It is assumed that a user with access to the parent course version is entitled to see all of its owning org units regardless of any org unit restrictions.)

 

 

not specifically for this block  (due to override) but users are restricted by their operational restrictions at the course version - responsible org unit level.

CRSF1230 Maintain Course Group Membership

 

Course Version

this form is always entered in context from CRSF1210 where restricted select applies

 

 

can never operate on the context record

Course Group Membership

no

although course groups can optionally be associated with an OU, the course group code LOV is not restricted

 

no

CRSF1240 Maintain Course Alternative Exits

 

Course Version

this form is always entered in context from CRSF1210 where restricted select applies

 

 

can never operate on the context record

Alternative Exit

no

 

 

no

CRSF1250 Maintain Course Awards

 

 

Course Version

this form is always entered in context from CRSF1210 where restricted select applies

 

 

can never operate on the context record

Course Award

no

 

 

no

Course Award Ownership

no (org unit restrictions have been overridden for this block. It is assumed that a user with access to the parent course award is entitled to see all of its owning org units regardless of any org unit restrictions.)

 

 

not specifically for this block  (due to override) but users are restricted by their operational restrictions at the course version - responsible org unit level.

CRSF1260 Maintain Course Fields of Study

 

Course Version

this form is always entered in context from CRSF1210 where restricted select applies

 

 

can never operate on the context record

Course Field of Study

no

 

 

no

CRSF1270 Maintain Course Categorisations

 

Course Version

this form is always entered in context from CRSF1210 where restricted select applies

 

 

can never operate on the context record

Course Categorisation

no

 

 

no

CRSF1280 Maintain Course Offering Unit Sets

 

Course Offering

yes (retrieves only course offerings for which user has org unit select restriction)

 

course version - responsible OU

can never operate on the context record

Course Offering Unit Set

yes (not obvious to users as always in context)

 

 course version - responsible OU

yes

CRSF1281 Maintain Course Offering Unit Set Relationships

 

 

Superior Course Offering Unit Set

yes (not obvious to users as always in context)

 

 

no

Course Offering Unit Set

yes (retrieves only course offering unit sets for which user has org unit select restriction)

 

course version - responsible OU

can never operate on the context record

Subordinate Course Offering Unit Set

yes (not obvious to users as always in context)

 

 course version - responsible OU

no

CRSF1282 Maintain Course Offering Option Unit Sets

 

Course Offering Option

yes (retrieves only course offering options for which user has org unit select restriction)

 

course version - responsible OU

can never operate on the context record

Course Offering Option Unit Set

yes (not obvious to users as always in context)

 

 

yes

CRSF1290 Maintain Course Reference Codes

 

Course Version

this form is always entered in context from CRSF1210 where restricted select applies

 

 

can never operate on the context record

Course Reference Code

no

 

 

no

CRSF12A0 Maintain Restricted Funding Sources

 

Course Version

this form is always entered in context from CRSF1210 where restricted select applies

 

 

can never operate on the context record

Funding Source Restriction

no

 

 

no

CRSF12C0 Maintain Course Annual Load

 

 

Course Version

this form is always entered in context from CRSF1210 where restricted select applies

 

 

can never operate on the context record

Course Annual Load

no

 

 

 no

Course Annual Load Unit Link

no (title may not display for restriction affected units)

 Unit Code

Unit Version - Teaching Responsibility OU

no

CRSF12D0 Maintain Course Stages

 

Course Version

 yes (retrieves only courses for which user has org unit select restriction)

 

course version - responsible OU

 can never operate on the context record

Course Stage

 no

 

 

no

CRSF12E0 Maintain Course Version Notes

 

Course Version

this form is always entered in context from CRSF1210 where restricted select applies

 

 

can never operate on the context record

Course Version Note

 no

 

 

no

CRSF12F0 Maintain Course Stage Types

 

no

 

 

no

CRSF1300 Maintain Course Offerings

 

 

Course Version

 this form is always entered in context from CRSF1210 where restricted select applies

 

 

 can never operate on the context record

Course Offering

 yes (not obvious to users as always in context)

 

 course version - responsible OU

 yes

Course Offering Instance

 yes (not obvious to users as always in context)

 

 course version - responsible OU

yes

CRSF1320 Maintain Course Offering Option Admission Category

 

 

Course Offering Option

 this form is always entered in context via CRSF1210 where restricted select applies

 

 

 can never operate on the context record

Admission Category

 no

 

 

 no

Admission Category Unit Set Restriction

 no

 Unit Set Code

 course version - responsible OU

no

CRSF1340 Maintain Course Offering Notes

 

Course Offering

 this form is always entered in context via CRSF1210 where restricted select applies

 

 

 can never operate on the context record

Course Offering Note

 no

 

 

no

CRSF1400 Maintain Course Offering Options

 

Course Offering

 this form is always entered in context via CRSF1210 where restricted select applies

 

 

 can never operate on the context record

Course Offering Option

 yes (not obvious to users as always in context)

 

 course version - responsible OU

 yes

CRSF1420 Maintain Course Entry Point Reference Codes

 

Course Offering Option

 this form is always entered in context via CRSF1210 where restricted select applies

 

 

 can never operate on the context record

Course Entry Point Reference Code

 no

 Unit Set Code

 course version - responsible OU

no

CRSF1441 Maintain Course Pattern of Study

 

Course Offering

 yes (retrieves only courses for which user has org unit select restriction)

 

 

 can never operate on the context record

Pattern of Study

 no

 

 

no

CRSF1442 Maintain Course Pattern of Study Periods

 

 

Pattern of Study

 this form is always entered in context from CRSF1441 where restricted select applies

 

 

 can never operate on the context record

Pattern of Study Period

 no

 

 

 no

Pattern of Study Unit

 no

 Unit Code

 Unit Version - Teaching Responsibility OU

 no

CRSF1450 Maintain Course Offering Option Notes

 

Course Offering Option

 this form is always entered in context from CRSF1400 where restricted select applies

 

 

 can never operate on the context record

Course Offering Option Note

 no

 

 

no

CRSF1500 Maintain Course Offering Patterns

 

Course Offering Instance

 yes (retrieves only courses for which user has org unit select restriction)

 

 

 can never operate on the context record

Course Offering Pattern

 yes (not obvious to users as always in context)

 

 course version - responsible OU

 yes

CRSF1510 Maintain Course Offering Pattern Notes

 

Course Offering Pattern

 this form is always entered in context from CRSF1500 where restricted select applies

 

 

 can never operate on the context record

Course Offering Pattern Note

 no

 

 

no

CRSF1700 Maintain Course Version Rules

 

Course Version

 yes (retrieves only courses for which user has org unit select restriction)

 

 

 can never operate on the context record

Course Version Rule

 no

 

 

no

CRSF2110 Maintain Disciplines

 

 no

 

 

no

CRSF2120 Maintain Unit Categories

 

Unit Category

 no

 

 

no

Unit Categorisation

 no (short title will not display for restriction affected units)

Unit Code

 Unit Version - Teaching Responsibility OU

 no

CRSF2130 Maintain Unit Set Statuses

 

 no

 

 

no

CRSF2140 Maintain Unit Levels

 

 no

 

 

no

CRSF2150 Maintain Unit Modes

 

 no

 

 

no

CRSF2160 Maintain Unit Classes

 

 no

 

 

no

CRSF2180 Maintain Unit Internal Course Levels

 

 no

 

 

no

CRSF2210 Maintain Basic Unit Details

 

  yes (retrieves only units for which user has org unit select restriction)

 Org Unit

Organisational unit

yes

CRSF2220 Maintain Teaching Responsibility

 

Unit Version

  this form is always entered in context from CRSF2210 where restricted select applies

 

 

 can never operate on the context record

Teaching Responsibility

no (org unit restrictions have been overridden for this block. It is assumed that a user with access to the parent unit version is entitled to see all of its teaching responsibility org units regardless of any org unit restrictions.)

 

 

 not specifically for this block  (due to override) but users are restricted by their operational restrictions at the unit version - owning org unit level.

CRSF2230 Maintain Unit Disciplines

 

Unit Version

   this form is always entered in context from CRSF2210 where restricted select applies

 

 

 can never operate on the context record

Unit Discipline

 no

 

 

no

CRSF2240 Maintain Course Unit Level

 

Unit Version

   this form is always entered in context from CRSF2210 where restricted select applies

 

 

 can never operate on the context record

Course Unit Level

 no

 

 

no

CRSF2250 Maintain Sub-Unit Relationships

 

 

Superior Unit Versions

  no (title, unit status may not display for restriction affected units)

 Unit Code

Unit Version - Teaching Responsibility OU

 no

Unit Version

   this form is always entered in context from CRSF2210 where restricted select applies

 

 

 can never operate on the context record

Subordinate Unit Versions

no (title, unit status may not display for restriction affected units)

 Unit Code

 Unit Version - Teaching Responsibility OU

 no

CRSF2260 Maintain Unit Categorisations

 

Unit Version

   this form is always entered in context from CRSF2210 where restricted select applies

 

 

 can never operate on the context record

Unit Categorisation

 no

 

 

no

CRSF2270 Maintain Unit Reference Codes

 

Unit Version

   this form is always entered in context from CRSF2210 where restricted select applies

 

 

 can never operate on the context record

Unit Reference Code

 no

 

 

no

CRSF2280 Maintain Unit Version Notes

 

Unit Version

   this form is always entered in context from CRSF2210 where restricted select applies

 

 

 can never operate on the context record

Unit Version Note

 no

 

 

no

CRSF2310 Maintain Unit Offerings

 

 

Unit Version

   this form is always entered in context from CRSF2210 where restricted select applies

 

 

 can never operate on the context record

Unit Offering

  yes (not obvious to users as always in context)

 

 course version - responsible OU

 yes

Unit Offering Pattern

  yes (not obvious to users as always in context)

 

 course version - responsible OU

 yes

CRSF2330 Maintain Unit Offering Notes

 

Unit Offering

   this form is always entered in context via CRSF2210 where restricted select applies

 

 

 can never operate on the context record

Unit Offering Note

 no

 

 

no

CRSF2410 Maintain Unit Offering Pattern Notes

 

Unit Offering Pattern

   this form is always entered in context via CRSF2210 where restricted select applies

 

 

 can never operate on the context record

Unit Offering Pattern Note

 no

 

 

no

CRSF2500 Maintain Unit Offering Options

 

Unit Offering Pattern

   this form is always entered in context via CRSF2210 where restricted select applies

 

 

 can never operate on the context record

Unit Offering Option

   yes (not obvious to users as always in context)

 

 course version - responsible OU

 yes

CRSF2520 Maintain Teaching Responsibility Overrides

 

Unit Offering Option

yes (retrieves only units for which user has org unit select restriction)

 

 Unit Version - Teaching Responsibility OU

 can never operate on the context record

Teaching Responsibility Override

 no (org unit restrictions have been overridden for this block. It is assumed that a user with access to the parent unit offering option is entitled to see all of its teaching responsibility org units regardless of any org unit restrictions.)

 

 

not specifically for this block  (due to override) but users are restricted by their operational restrictions at the unit version - teaching responsibility org unit level.

CRSF2530 Maintain Unit Offering Option Notes

 

Unit Offering Option

  this form is always entered in context via CRSF2210 where restricted select applies

 

 

 can never operate on the context record

Unit Offering Option Note

 no

 

 

no

CRSF2700 Maintain Unit Version Rules

 

Unit Version

yes (retrieves only units for which user has org unit select restriction)

 

 Unit Version - Teaching Responsibility OU

 can never operate on the context record

Unit Version Rule

 no

 

 

no

CRSF4110 Maintain Special Requirements

 

 no

 

 

no

CRSF4120 Maintain Unit Set Categories

 

 no

 

 

no

CRSF4130 Maintain Unit Set Statuses

 

 no

 

 

no

CRSF4200 Maintain Unit Sets

 

Unit Set

 no restriction on unit sets (Responsible OU display is affected by org unit restrictions)

 

 

 no

Unit Set Course Type Restriction

 no

 

 

no

CRSF4201 Apply Unit Set to Course Offerings

 

Unit Set

 no

 

 

 no

Course Offering

 yes (retrieves only courses for which user has org unit select restriction)

Course Code

 course version - responsible OU

can never operate on records in this block

Org Unit Code

Organisational unit

CRSF4210 Maintain Unit Set Notes

 

 no

 

 

no

CRSF4230 Define Unit Set Rules

 

no

 

 

no

 

Inquiry Facility

Form

Block

Restricted Select (impact)

Restrictions in LOV

Restricted by

Operation Restrictions

INQF1110 Person Address Inquiry

 

 

Person

 no

 

 

 Inquiry only form

 

 

Correspondence Address

 no

 

 

Other Addresses

 no

 

 

INQF1200 Student Course Attempt Inquiry

 

 

 

 Student Course Attempt -

yes. (retrieves only courses for which user has org unit select restriction) Records retrieved on entry to the form via INQF1A00. Queries cannot be performed in this block.

 

 student course attempt - course version - responsible org unit

 Inquiry only form

 

 

 

 Student Unit Set Attempt

 yes

 

 unit set attempt - course attempt - course version - responsible org unit

 Student Unit Attempt - Academic Details

 yes

 

 unit attempt - course attempt - course version - responsible org unit

 Student Unit Attempt - Administrative Details

 yes

 

 unit attempt - course attempt - course version - responsible org unit

INQF1241 Advanced Standing Unit level Inquiry

 

 Advanced Standing

 yes (retrieves only courses for which user has org unit select restriction)

 

 course version - responsible org unit

 Inquiry only form

 

 Advanced Standing Unit Level

 yes

 

 course version - responsible org unit

INQF1242 Advanced Standing Unit Inquiry

 

 

 Advanced Standing

 yes (retrieves only courses for which user has org unit select restriction)

 

 course version - responsible org unit

 Inquiry only form

 

 

 Advanced Standing Unit

 yes (title, unit status may not display for restriction affected units)

 

 Unit Version - Teaching Responsibility OU

 Alternate Units

 yes (title, credit pts may not display for restriction affected units)

 

 Unit Version - Teaching Responsibility OU

INQF12E0 Class List Inquiry

 

 

 Class Details

yes (retrieves only units for which user has org unit select restriction)

 

 Unit Version - Teaching Responsibility OU

 Inquiry only form

 

 

 Student Unit Attempt

 yes (retrieves only student unit attempts in courses for which user has org unit select restriction)

 

 student course attempt - course version - responsible org unit

 Download Records function

 yes (downloads only student unit attempts in courses for which user has org unit select restriction)

 

 student course attempt - course version - responsible org unit

INQF1A00 Person Inquiry

 Person

 no

 

 

 Inquiry only form

 

 Student Course Attempt

 yes (retrieves only course attempts for courses for which user has org unit select restriction)

 

 course version - responsible org unit

 

INQF1A10 Person Query Summary

 

 yes (retrieves only course attempts for courses for which user has org unit select restriction)

 

 course version - responsible org unit

Inquiry only form

ENRR08M0 Academic History Report

 

 yes (retrieves only course attempts for courses for which user has org unit select restriction)

Parameter LOV (when run from menu) - Responsible Org Unit

 student course attempt - course version - responsible org unit

 Report

  

Last Modified on 11 March 2002