What's new in Security and Administration (Planning Space 16.5)

Release 16.5 Update 25 (version 16.5.25)

Audit Log

New OData API endpoint '/planningspace/data/v1/auditlogs' for access to log data.

Release 16.5 Update 22 (version 16.5.22)

Global price decks: Security permissions for folders in Price Management

Security permissions have been added to folders in the Price Management interface (accessible in the Dataflow Configuration or Economics Configuration workspaces).

Folder permissions are inherited. The permissions of a parent folder will be applied to new child nodes (folder or Price Deck) that are added to the folder. You can use this feature to set default permission settings which new Price Decks will automatically inherit.

Security permissions for the Economics and Financials loaders in Dataflow

Permissions controls on batch import settings and mapping templates have been added to the data loader tools Load from Economics and Load from Financials.

Security permissions for report templates (Economics and Financials)

Security permissions can be applied to report templates and folders in the Report Designer in the Configuration workspace.

The permissions control a user's access to use or modify the templates. A user must be granted 'Read' access to view a template in the Report Designer, and to use the template in Result Set reporting and scratchpad calculations.

Folder permissions are inherited. The permissions of a parent folder will be applied to new child nodes (folder or template) that are added to the folder. You can use this feature to set default permission settings which new report templates will automatically inherit.

See Report Designer.

Regime Library: Security permissions for folders (Economics and Financials)

Permissions have been added on folders in the Regime Library workspace. The permissions of a parent folder will be applied to new child nodes (folder or Regime) that are added to the folder. You can use this feature to set a default permission setting which new Regimes will automatically inherit. See Regime Library workspace.

Release 16.5 Update 17 (version 16.5.17)

Global price decks: Security permissions for decks and price groups

Security permissions can be applied to individual global price decks, and separate permissions can be applied to the price groups within decks. These permissions control how price deck information can be viewed and used in Dataflow and Economics (see Permissions for price decks and price groups).

Economics Hierarchy security

Security permissions have been added for price groups within hierarchy price decks. These are replacements for the Document-level permissions for price decks introduced in Update 15. See Deck permissions for the hierarchy Currency deck and Price deck

Login alert message

The Planning Space application tenant setting 'Login Alert Message' can be used to set an alert message which is displayed to users during login. For example, to warn about planned system events. See Login alert message.

Windows domain authentication for the Dataflow 'Load from Database' tool

The tool now supports the use of Windows authentication when the Server Side Load option is used via API. See Server Side Load authentication.

Release 16.5 Update 16 (version 16.5.16)

Authentication via Identity Provider

Added support for user client logins to be initiated by an Identity Provider server; this allows sign-ins from an IdP web portal page, if this is supported by the IdP.

License profiles

License Profile feature in IPS Manager for the management of license affinity and the assignment of licenses. See the Planning Space 16.5 Deployment Guide.

Reconciliation permissions

Added permissions at the reconciliation level. These control when a user will be allowed to modify node data during a 'Load Data' operation. (Note: for existing reconciliations after upgrading, 'Full Access' permissions will be granted to the 'Everyone' workgroup to maintain compatibility with the previous version; if permissions controls are going to be used then the Everyone permission for each reconciliation should be modified or removed.)

Release 16.5 Update 15 (version 16.5.15)

Security settings 'Workgroups to assign to new hierarchies'

The single setting 'Workgroups to assign to new hierarchies' for Economics/CASH/Financials has been split into separate settings for Economics/CASH or Financials.

Economics and Financials hierarchy security

Added instance-level permissions for hierarchy currency decks and price decks. See Deck permissions for the hierarchy Currency deck and Price deck.

Economics and Financials Result Set security

Added permissions to folders in the Result Set Explorer. See Result Sets.

Release 16.5 Update 13 (version 16.5.13)

User access control via authentication method

Authentication methods (Local, SAML2, Windows AD) can be individually enabled/disabled for each tenant, using the IPS Manager (note: if SAML2 is the only allowed authentication then login at the Planning Space screen will be bypassed).

Workgroup management

Security workgroups can be renamed.

Dataflow 'Load from Database' tool permissions

Added independent security permissions for batch import settings and mapping templates.

Release 16.5 Update 12 (version 16.5.12)

Automatic provisioning of SAML2 user accounts

A new tenant user account can be created automatically when a user logs in to Planning Space for the first time using an account that is defined (and enabled to access PlanningSpace) by the Identity Provider's domain user services. For configuration details see the Planning Space 16.5 Deployment Guide.

Workgroup management

New Copy Workgroup function.

New Copy from workgroup button so that users can be assigned membership of a workgroup by copying the user membership from another workgroup.

New 'invert selections' button in the user membership editor for a workgroup (this is useful, for example, in the case of switching Dataflow document permissions between a specified list of allowed users and a list of denied users).

Release 16.5 Update 11 (version 16.5.11)

Audit log

Logins via the API and selected API interactions are now recorded in the application audit log.

New role for printing control

New security role 'Configuration/Reports - Print' controls user access to print functions in the Planning Space application (the default setting includes 'Everyone' so that all users are granted the role).

PlanningSpace Data Connector

Improved logging mechanism so that logs are automatically written to a worksheet rather than being held in memory. The new mechanism requires at least the Office 2016 version of Excel with latest updates installed, or Office 365. In case of incompatible Excel versions this will be automatically-detected by the PDC code and the tool will not be usable.

Portfolio 'LpSolver' setting

The application setting 'LpServer' for Portfolio has been changed to the new default value 'https://solver.aucerna.app'.

Release 16.5 Update 7 (version 16.5.7)

API key expiry

Added an administration option to set an expiration lifetime for API keys; the default setting is that keys have unlimited validity. See Generate API Key.

Client-side logging

Added client-side log files that are stored in the user's local machine.

Release 16.5 Update 2 (version 16.5.2)

Role changes for Currency Decks and Price Decks

There are new security roles 'Economics/Hierarchy Currencies- View' and 'Financials/Hierarchy Currencies- View' so that users can be blocked from viewing the values inside the Currency Decks that they are using. To avoid confusion the existing role 'Economics/Hierarchy - Currencies' has been renamed to 'Economics/Hierarchy Currencies - Configure', and likewise for the Financials roles.

There is a new security role 'Economics/Hierarchy Prices - View' so that users can be blocked from viewing the price values inside the Price Decks that they are using. To avoid confusion the existing role 'Economics/Hierarchy - Prices' has been renamed to 'Economics/Hierarchy Prices - Configure'.

Release 16.5 (version 16.5.0)

Role changes

The new security roles 'Economics/Hierarchy - Currencies', 'Economics/Hierarchy - Prices', and 'Financials/Hierarchy - Currencies' have been added to improve security within hierarchies. The new roles are required to replace the currency or price deck in a hierarchy, to rename a deck, and to edit the deck content. The default settings are 'Allowed' access granted to all users (i.e., the 'Everyone' workgroup), so that backwards compatibility with Planning Space 16.4 is maintained.

Authentication and Single Sign-On

SSO is now implemented for login to the tenant webserver followed by launching of the Planning Space client application. Therefore users do not need to re-enter their credentials. The IPS service setting 'Launch Code Validity Period' determines the validity period for SSO (default is 15 seconds).