OneStream Security Essentials

Introduction

Someone once said to me, “Teresa, you are passionate about OneStream security.” I had to think about that for a moment. I mean, I am passionate about a lot of things – travel, speaking foreign languages, certain sports and sporting teams, family, and being the best aunt I can be – but OneStream security? The thought had not crossed my mind, but that moment became the inspiration for this book.

I am passionate about sharing what I understand to help others in their learning journey, whether it be as a consultant on their first or tenth OneStream project, a new system administrator, or a seasoned finance professional. I enjoy sharing my knowledge and the best practices learned in my career, and hopefully picking up new knowledge myself along the way. Any wisdom I can impart to make someone else’s work life easier, or a company’s OneStream system more secure, I am happy to do so. So, yes, by that definition, I am passionate about OneStream security!

Introduction

Overview

Like death and taxes, system security is unavoidable. No matter how simple (or complex) an organization may be or how few (or many) users a company has, granting everyone or nobody access, while possible, is not practical. So, where does that leave you?

How you design, implement, and maintain your OneStream security is a balancing act between data governance and ease of use, between adequately controlling and easily maintaining. OneStream does not dictate how simple or complex your security model will be. You, as an administrator or consultant, will have to determine the best overall approach to meet your company’s needs. This book will give you not only an in-depth understanding of how security works, but will also cover common approaches, best practices, and everything you want to know as you tackle the design, implementation, and maintenance of your OneStream security.

Metaphor time. Think of system security in the same way as securing a new house. In the beginning (the design phase), when you are just starting construction, there is not much to secure, and the building site is open. As construction on your home progresses (the build phase), you may add fencing and put in a temporary lock to secure building materials. Finally, when the construction is complete and you are ready to move in (go-live), you will have to decide how you want to secure your new home from that point forward (maintain).

Sure, you could leave all your doors and windows unlocked (i.e., ‘Everyone’ has access), but that is not realistic. You could lock everything down (i.e., ‘Nobody’ has access), but that is also not an option. Therefore, you will likely choose some intermediate level of security by using deadbolts, fencing, cameras, motion detectors, and other alarm systems. How much effort and cost you put into securing your home will depend on how many members are in your family, the ages of family members, if you have a lot of valuables, how large your house is, and your tolerance for feeling safe.

OneStream security is similar. Early in a project life cycle, there is no need to secure many items. But as a project progresses, you have to start considering what and how you want to secure, and what layers or checkpoints you want to add to your security framework. You will have to consider things like your user base, your CFO, your IT department, and your auditors, as well as what data is stored in OneStream, any audit or governance requirements, and your company’s risk tolerance versus its need for control. All these things will need to be taken into consideration as you walk the line between data governance, ease of use, control, and maintenance.

Keep in mind that while you may have an initial security strategy, it can change over time, even after go-live. Just like with home security, you may not install cameras at first, but then – after living in your home for a couple of years – decide to install those security cameras after all.

OneStream security is similarly flexible in that, while you want to have an upfront methodology and approach, it can change over time to meet your changing business or company needs.

As we progress through this book, we will talk about the different layers to OneStream security…

  • Framework and Environment

  • Users and Groups

  • Application Objects

  • System Objects

  • Metadata

  • Workflows

… and how these layers work together to form your overall security model and user experience within OneStream. OneStream allows for flexibility in how every company secures its data, allowing companies to tailor each of the layers to meet their company needs.

So that brings us to the three native security groups that exist in every customer environment: Everyone, Nobody, and Administrators. Additionally, there is one native user that exists in every customer environment, the Administrator.

These three groups and one user are set up from day one in any OneStream environment, and exist across every company using OneStream. As we will learn later, they serve different purposes within your application and environment, and can be leveraged in different ways to achieve your security model.

Where you go from these three groups and one user will depend on your company’s needs. You, along with your implementation team, will decide a methodology or framework for how you want your security to work and be maintained.

Security is used within OneStream not only to control access to data and sensitive information, but also to drive the end-user experience. You can use your OneStream security to limit what people can and cannot see, not only to secure access within an application, but also to create a simplified user experience (e.g., why does someone in Europe need to see something related to a workflow process in Mexico?).

As you read this book, keep these data security and user experience goals in mind. And, as mentioned before, also keep in mind the balance between data governance, ease of use, control, and maintenance as they will all play a role in how you shape your security.