User Information
The User Information (SCUSER) page is used to review and manage user information, such as password information, home organization codes and account options for an existing user in the system. Please see the Add User Information page when you want to add a record.
Row-level actionsRow-level actions
The following row-level actions are available on the User Information search page.
-
Assign Security Role to User - A transition to the Assign Security Role to User page, which allows users to add or remove Security roles to the selected user in edit mode.
-
User Login Access - A transition to the User Login Access page for the selected record in edit mode, to add/revoke user login access.
-
User to Business Role Association - A transition to the User to Business Role Association page for the selected record, to associate business roles to the user. In a LDAP configuration setting, this row level action will be labeled as LDAP User to Business Role Association and will transition the user to the LDAP User to Business Role Association (LUSRBROL) page.
-
Manage Approvers
-
Assign Roles - A transition to the Assign Roles to Approver page in edit mode for the selected user.
-
Alternate Approval Assignments - A transition to the Alternate Approval Assignments page to assign work units to another user or approval role now or in the future to another user or approval role for the selected role.
-
Copy Workflow Roles - A transition to the Copy Workflow Rules page, which allows you to select a User ID and copy one or more workflow (approval) roles from that user to another for the selected record.
-
Related Pages
-
Action Log - A transition to the Action Log page, which presents a history of logged actions for the selected user.
-
Approval Log - A transition to the Approval Log page, which allows you to view a log of approval actions applied to transactions.
-
Foreign Organization - A transition to the Foreign Organization page to define additional organizational entities a user can or cannot access in addition to the home organization.
-
Historical Tracking of Assignments - A transition to the Historical Tracking of Assignments page, which presents historical details of any assignment or revocation actions done.
This page has two tabs:
Field |
Description |
Name |
A concatenation of First Name and Last Name |
Last Name |
The last name of a user. |
First Name |
The first name of a user. |
Locality |
A description intended to be the locality of where the user is primarily located. |
Room |
A description intended to be the room, office, cubicle, or other type of space where the user is primarily located. |
|
The email address of the user for internal CGI Advantage email use. |
Phone / Extension |
The phone and optional extension for the user. |
Field InformationField Information
Field |
Description |
User ID |
The unique identification of a user. |
Name |
A concatenation of First Name and Last Name. |
Home Organization Codes |
The values entered for Home Organization codes are used during security authorization to authorize the user’s access to secured resources. Leaving an organization field blank implies that the user has access to all organizational values at that level. Note: These organizational fields are not validated against the organization tables in the system. This means that it is possible for incorrect codes or incorrect combinations of codes to be entered. Special care should be taken when setting up these values. |
Infer Home Department and Unit |
In the event that a user has access to only a single Department or Department/Unit so that the creation of transactions should always default the Home Department and any Home Unit, this indication is the first configuration point to make that happen. The second location is Transaction Control (DCTRL). Users that access multiple Departments or multiple Units within a Department can use this feature to default a value or values, however, they will have to remember to override before or after defaulting for cases with the ‘home’ values are not desired. When set to true, the system will infer a user's Home Department and any Home Unit defined through security configuration while creating a transaction. This can occur in a number of places: Transaction Catalog, Copy Transaction, Copy Forward Transaction, and a collection of locations with a specialized action to create a transaction based on the selected data. Of this last type of location, there are some with specialized logic that do not use this feature as there is different logic to determine a Department and Unit (for example, Matching Status). Furthermore, if a user creates a transaction through batch processing or spreadsheet upload, then the inference will not happen even if the indication is true. |
Override Errors |
The Override Error level assigned to a user for overriding errors. Configuration on Security Role and Access Control interact with this setting. Please see those two locations for complete override information. |
Bad Logins Count |
A system-maintained number of bad logins for the user since their last successful login. |
Bad Password Reset Count |
A system-maintained number of bad password resets for the user since their last successful reset. |
Locked Out |
This field represents the state of the user account with the following values:
The Locked value can be set automatically by Advantage in one of two situations:
|
Logging |
When selected, the system creates a new application user from an existing LDAP user entry. When selected, the system will also log all of the user activity for the user into the security logs. |
Alert Email Notification |
When selected and if the user is the recipient of an Alert or Broadcast message, then the email address is used to deliver the message. When selected, the Email field is required. |
Alert SMS Notification |
When selected and if the user is the recipient of an Alert or Broadcast message, then the phone number is used to deliver the message. When selected, the Phone field is required. |
Last Login Date |
The date of the last successful login by a user as recorded by the system upon login. This date is used to edit for inactivity for the defined period of time before locking out a user. |
Disable User Business Card |
Select this to disable the User Business Card functionality for the user. This is useful for service accounts or when you want to protect users’ identity and contact information, such as users in public safety. |
Last Password Change Date |
The date of the last successful password change as recorded by the system. This date is used to compute password ages to enable prompts to reset and ultimately locking out a user if not changed. |
Password |
The current password for a user, which is encrypted and not displayed online. |
Confirm Password |
Not required unless changing a password. |
Email Password |
User's password for the email account specified in the Email Address Field. |
Confirm Email Password |
User's password for the email account specified in the Email Address Field. |
Expire New Password |
When selected, the new password set/reset by the administrator will expire after the user logs in for the first time. The user will have to change the password to one of their choosing before accessing the system further. |
User Security Realm |
This field is for protecting Web Logic resources. Each security realm consists of a set of configured security providers, users, groups, security roles, and security policies. A user must be defined in a security realm in order to access any Web Logic resources belonging to that realm. |
Applications |
This section indicates what section of CGI Advantage that a user can access. |
External Directory Information |
The External Directory Information field uniquely identifies the user in the external user directory / repository that the application delegates the authentication function to. For example, if the external user repository is the LDAP compliant Microsoft Active Directory, then the user's record's values for attributes like ‘SamAccountName’ or ‘UserPrincipalName’ uniquely identify the user within the designated security realm and may be used. Note that the attribute used for the security realm is specified in the security configuration for the application (csf.properties). |
Reporting User Information |
This field captures the Reporting Application User ID used by the Advantage application to integrate reports and inquire reporting data from the Reporting application. If the Reporting User ID is blank, then the Reporting application will use the logged in Advantage User ID for Row Level Security. For Advantage Insight Reporting, Reporting User ID is optional and can be kept blank, the logged in Advantage User ID is passed to Insight for Row Level Security. |
Disable Dual Factor Authentication |
This flag controls the Dual Factor Authentication (DFA) status for the user. When this check box is selected (set to true), DFA is disabled for the user; otherwise, DFA remains enabled. |
Registered Email |
A display of the registered email address for the user. A token is sent to this email address when the dual-factor authentication feature is enabled and the Token Preference is set to Email. If this field is left blank, then the value provided in the Email Address field on the User tab is inferred when saving. |
Registered Phone |
A display of the registered phone number of the user. A token is sent to this phone number via SMS when the dual-factor authentication feature is enabled and the Token Preference is set to SMS. If this field is left blank, then the value provided in the Phone Number field on the User tab is inferred when saving. Please ensure that the number entered can receive the token via SMS.
|
-
Assign Security Role to User - A transition to the Assign Security Role to User page, which allows users to add or remove Security roles to the selected user in edit mode.
-
User Login Access - A transition to the User Login Access page for the selected record in edit mode, to add/revoke user login access.
-
User to Business Role Association - A transition to the User to Business Role Association page for the selected record, to associate business roles to the user.
-
Manage Approvers - A transition to the Manage Approvers page, which allows approval assignment for the selected user.
-
Action Log - A transition to the Action Log page, which presents a history of logged actions for the selected user.
-
Approval Log - A transition to the Approval Log page, which allows you to view a log of approval actions applied to transactions.
-
Foreign Organization - A transition to the Foreign Organization page to define additional organizational entities a user can or cannot access in addition to the home organization.
-
Historical Tracking of Assignments - A transition to the Historical Tracking of Assignments page, which presents historical details of any assignment or revocation actions done.