Authorization concepts that scale with the organisation — from characteristic-level analysis authorizations to a custom cockpit managing multiple auth-relevant dimensions.
Reporting security is more than roles: analysis authorizations restrict at characteristic, hierarchy-node and key-figure level — and must hold consistently across queries, planning functions and every frontend.
Entity, region, market, local versus consolidated view — real organisations restrict along several dimensions at once. Modelled naively, the combinations explode; modelled well, they stay maintainable.
Generated rather than hand-maintained authorizations are transparent by construction: every value traceable to a business decision, every change documented — a natural fit for regulated environments.
I designed and built a custom cockpit-based authorization concept: business owners maintain multiple auth-relevant dimensions in a single interface, and the corresponding analysis authorizations are generated automatically — consistent, auditable and dramatically cheaper to administer. Field-level authorization design goes back as far as my Coop Hungary project.