Security Roles and Domains

This section introduces you to the concepts of security roles and domains. An understanding of both concepts is required in order to configure and manage security in Cornerstone Saba. Essentially, security roles define sets of access privileges in the system. Domains organize the components of a company's Cornerstone Saba business data into a hierarchical structure.

Security Role model

Cornerstone Saba supports the Security Role model to establish the relationship between a user, a set of security privileges (a security role), and the domain in which the user can use those security privileges at a different point.

In the Security Role model, a security role defines a set of component privileges. The role does not define the domain associations. You would then assign the security role to one or more people, and associate the domain to the combination of the person and the security role. Because security roles are "generic" in the domain sense, you can assign any role to any individual whose requires the role. When you assign a person to a security role, you specify the domain in which the person can use the role.

The advantage of the Security Role model is that you can reuse a single "generic" security role by assigning the role to people in multiple domains. From a business standpoint, this model best fits companies whose job roles are replicated across the company - a specific job role in one office has the same duties and tasks as the same job role performed in another office.

For example, suppose your company has offices in the United States and Canada, each with its own domain in Cornerstone Saba. Also suppose your company's instructors in both countries deliver instructor-led training and perform other, similar functions in their respective domains. In this case, you could create a single security role with the necessary instructor-related component privileges. When you assign the role to United States instructors, you would associate the combination of the person and security role to the United States domain. When you assign the same role to Canada instructors, you would associate the combination of the person and security role to the Canada domain.

When you assign privileges on a component within a certain domain, the privileges also apply to any child domains. For example, if the United States domain contained several functional domains, such as Sales and Marketing, any privileges granted at the United States level are also given in the Sales and Marketing domains. All privileges granted at the parent domain level apply equally to any child domains.

Note: If you grant privileges on a component in a parent domain, you cannot remove them from the child domains. For example, if a role grants users the ability to edit a particular component in the world domain, users assigned the role can edit component records in any children domains. You can grant additional privileges in child domain records, but you cannot remove privileges defined in a parent domain.

Each time a new internal or external person is created in the system, the system automatically assigns the person basic privileges necessary to perform the associated learner tasks. The list of roles assigned to people automatically is hard-coded.

You can assign additional security roles as needed. You can associate people with multiple security roles. This flexibility enables you to assign only those privileges needed by users in order to successfully complete their learning or administrative tasks.

In summary:
  • If you want to establish different privileges for similar user groups, you will need multiple security roles.
  • If you want to establish the same privileges for similar user groups, but in different domains, you will need only one security role.