CHRS Knowledge Base

Security Frequently Asked Questions (FAQ)

Updated on

This document is to provide campus users with a list of frequently asked questions regarding Security.  

Distributed Security Administrators (DSA’s)

Who is a Distributed Security Administrators (DSA’s)?

Campus will need to submit a ServiceNow request using the CHRS Security Access Request form. Only campus authorized requestors will be allowed to submit the request.

How does a DSA receive access to Distributed User Profiles? 

They will have to submit a CMS Data Center Campus Security Administrator “CSA” Application in order to gain access

Will campuses still have access to their DS (View Access) HR accounts once in CHRS PRD?

Campuses will not have DS Oracle accounts in production.

Will campuses get development access in CHRS? 

No. CHRS development will be handled by the CMS central. Campus-specific modifications to CHRS are not allowed. Therefore, campus development access will not be authorized, unless it is granted to support a specific CHRS Program workstream activity.

Will campuses still have access to their DU (Direct Update) HR accounts once in CHRS PRD?

Campuses will not have DU Oracle accounts in production.

Dynamic Roles

What is a Dynamic Role?

When the specified rules are met, these roles will be automatically provisioned to users. Conversely, when the rules are no longer met, the roles will be deprovisioned from the users' profiles.

In CHRS how are Dynamic Roles defined?

Dynamic role rules in CHRS are defined or coded using PeopleSoft Query, PeopleCode, or the Lightweight Directory Access Protocol (LDAP) directory. We have specifically chosen to utilize the Query Rule Enabled and PeopleCode Rule Enabled (Recruiting Only) feature for several security roles in CHRS. 

How are the Dynamic Roles automatically assigned?

The application engine program DYNROLE_PUBL is responsible for assigning dynamic roles based on the query logic that retrieves a list of operator IDs. The DYNROLE_PUBL batch job will be centrally managed by CMS and scheduled to run hourly from 4 am to 8 pm, Monday to Friday.

How do you view the Dynamic Roles assigned to a user?

To view the dynamic roles assigned to a user, you can navigate to the user profile page and access the roles tab, where they will be displayed along with other roles.

To view the dynamic roles assigned to a user, you can navigate to the user profile page and access the roles tab, where they will be displayed along with other roles.
Is there a list of all Dynamic roles for CHRS?

Yes, you can find a complete list of the Dynamic Roles in the CHRS Library, located under the Security Tile.

Where should a campus go to locate a list of all Dynamic Roles for CHRS?

A complete list of the Dynamic Roles can be found in the CHRS Library, located under the Security Tile.

Roles

Is there a list of all roles for CHRS?

A complete list of the roles can be found in the CHRS Library, located under the Security Tile.

Where should a campus go to locate a list of all roles for CHRS?

A complete list of the roles can be found in the CHRS Library, located under the Security Tile.

Who defined and maintains the Security Roles and Permission lists for CHRS? 

Security Roles and Permissions lists for CHRS are defined and maintained by the CHRS Security Team. A systemwide set of security roles and permission lists will support approved job functions required to implement the CHRS business practices defined and approved by Systemwide HR.

Will campuses have the ability to assign roles to their users themselves? 

Yes, campuses will have the ability to assign roles to users based on the job function(s).

Can a campus create/modify roles and permissions lists in a non-prod instance? 

Campuses will not be able to create or modify roles in either production or non-production environments. While campuses can create permission lists to define row-level security, they will not be able to add components to campus-specific permission lists.

Can a campus create/modify roles and permissions lists in production? 

No. Campuses can submit a request (ServiceNow Ticket) to the Central Security Office to implement those changes in PRD, supplying the required specific business need/function this addresses. The request will be reviewed by the CHRS Security Team, CMS Module Teams and approved by the Systemwide HR for inclusion in CHRS.

How can a campus request a new or modification to a role? 

Yes. Campuses can submit a request (ServiceNow Ticket) to the Central Security Office to implement those changes in PRD, supplying the required specific business need/function this addresses. The request will be reviewed by the CHRS Security Team, CMS Module Teams and approved by the Systemwide HR for inclusion in CHRS.

How do you find a role to a page?

Run the following PeopleSoft query: CSU_SEC_FIND_ROLE. The query will ask for you to Enter Page Name and then provide you with the associated role. 

What role would a user need to modify the NavBar? 

Campus users will not have a role that allows them to modify the NavBar. 

Once a page is added to the NavBar, do users have the option to remove it?

For CHRS, security will be in place so that users will not be able to add or remove from the NavBar.

How can a page be removed from the NavBar?

For CHRS, security will be in place so that users will not be able to add or remove from the NavBar.

Will DOB and SSN in CHRS 9.2 be masked for all users?

No, authorized user will need to one or more of the following security roles:

  • CHR_PT_Full_View_All
  • CHR_PT_Full_View_DOB
  • CHR_PT_Full_View_Driver_Lic
  • CHR_PT_Full_View_Passport_Nbr
  • CHR_PT_Full_View_SSN
In CHRS what fields will be masked (redacted)?

In CHRS, the following fields will be masked (redacted): DOB, SSN, Driver License, and passport number.

How does a campus know that a role should only be assigned at the CO level? 

Campuses can tell that a role is for CO only based by the short and long description. The description will have "COO" and the Long Description will have a note that it's CO Only.

Department Trees

Do campuses need to add all departments on the department table to the HR department tree in CHRS? We don't have the funding departments all on the tree at this time.

No, the campus Hierarchy and Department Security trees will be converted as part of the conversion process.  No additional changes are necessary for them.  It is recommended to run the Oracle delivered tree auditor in in their 9.0 production environment and take action as needed.

Process Monitor

In CHRS, do campuses have access to view other users jobs in Process Monitor for troubleshooting?

 Yes, users with access to the Process Monitor page can view jobs submitted by others, but they won't be able to access the results unless they have additional permissions.

If campuses are not allowed to have any on-campus users have access to view other users jobs in Process Monitor for troubleshooting, what will be the process for users with issues?

Campuses can access only campus-specific submitted jobs, and only if the 'ReportDistAdmin' role is assigned to their user profile.

In CHRS, do campuses have access to view other users jobs in Report Manager for troubleshooting?

No, users will only see output in their Report Manager page if they submitted the job themselves or were added to the job’s distribution by another user.

User Profiles

Since distributed user profiles won't have the ability to set or update PeopleSoft passwords, in the event that this is required (for example, a service account), what will be the process for the account password to be set and shared with the campus?

The campuses will need to submit a ServiceNow ticket requesting a password reset.

In CHRS can a campus delete User Profiles for inactive employees? 

No. All individuals in CHRS are required to have a User Profile, regardless of their status, and campuses will not have the ability to delete these profiles.

If campuses cannot delete User Profiles, how are duplicates handled?

In CHRS, there are various types of duplicates, each requiring a different approach for resolution. Campuses should consult the Managing Duplicates document found in the Integration section of the CHRS Knowledge Base.

End of Article.

0 Comments

Add your comment

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Previous Article (job aid) Security Delivered Queries for CHRS 
Next Article (job aid) Security Plan and Requirements
Do you need an article? Contact Us