Entitlements and Policy
How access is governed in the OpenTRMS Workbench — functional and data groups, grants, segregation of duties, and recertification.
Transcript1m 24s
In this walkthrough we'll see how access is governed, and why you can see what you can see, in the OpenTRMS Workbench.
The first walkthrough said that what you can see depends on your entitlements. The Access Policy Console is where those entitlements are actually defined.
Functional groups come first. A functional group is a bundle of permissions — the scopes column lists exactly what the group allows, which is what makes it auditable.
Data groups answer the other half of the question. Not what you may do, but which books, portfolios and counterparties you may do it to.
Grants are where the two meet a person. A grant ties a user to a group, and this is the record that explains why an individual has the access they have.
Segregation of duties is checked here too. Some combinations are not allowed together — booking a trade and approving it, for instance — and conflicts are surfaced rather than silently permitted.
And recertification closes the loop. Access is reviewed periodically rather than granted once and forgotten, which is what auditors will ask to see.
That completes Entitlements and Policy. Every surface shown here can also be opened from the agent panel on the right, by asking for it in plain English.
1. Open the Workbench
In this walkthrough we'll see how access is governed, and why you can see what you can see, in the OpenTRMS Workbench.

2. Open the Access Policy Console
The first walkthrough said that what you can see depends on your entitlements. The Access Policy Console is where those entitlements are actually defined.

3. Functional groups carry permissions
Functional groups come first. A functional group is a bundle of permissions — the scopes column lists exactly what the group allows, which is what makes it auditable.

4. Data groups carry reach
Data groups answer the other half of the question. Not what you may do, but which books, portfolios and counterparties you may do it to.

5. Grants tie groups to people
Grants are where the two meet a person. A grant ties a user to a group, and this is the record that explains why an individual has the access they have.

6. Segregation of duties
Segregation of duties is checked here too. Some combinations are not allowed together — booking a trade and approving it, for instance — and conflicts are surfaced rather than silently permitted.

7. Recertify access periodically
And recertification closes the loop. Access is reviewed periodically rather than granted once and forgotten, which is what auditors will ask to see.

8. Next steps
That completes Entitlements and Policy. Every surface shown here can also be opened from the agent panel on the right, by asking for it in plain English.