Skip to main content
Peakon
Last Updated: 2023-06-23
Setup Considerations: Access Controls

Setup Considerations: Access Controls

You can use this topic to help make decisions when planning your configuration and use of Access Control. It explains:
  • Why to set it up.
  • How it fits into the rest of Peakon.
  • Downstream impacts and cross-product interactions.
  • Security requirements and business process configurations.
  • Questions and limitations to consider before implementation.
Refer to detailed task instructions for full configuration details.

What It Is

Access control enables administrators to control group settings, regarding dashboards, employee records, and administration. Access controls work together with
Attributes
, to form the full scope of activities a user can perform within their assigned segments.

Business Benefits

Configuring each access control group with the relevant permissions ensures data security and the appropriate access level for stakeholders.
You can create your own custom access groups to diversify the access levels within your organization. Each group also enables you to bulk notify or export its members.

Use Cases

You can use access control groups to:
  • Control which groups have dashboard access.
  • Control which groups can view comments.
  • Control which groups have company level access.
  • Enable local administrator level access.
  • Enable specialist access for specific drivers.
  • Enable personal dashboards for your employees.

Questions to Consider

Question
Considerations
How many administrators do you need?
An administrator is the highest level user, with authority over the account and automatic access to all settings. Administrators can add and remove other administrators, and delete the entire account.
For security reasons, we recommend keeping the number of administrators to a minimum, ideally 2 or 3 people.
If other stakeholders need company level access, you can use the other
All employees
groups, such as Human Resources or Senior Leader, or create a custom group.
Which leaders require overall company level access?
You can set up multiple groups to enable different types of company level access. Examples: dashboard and comment access, employee management access,
Specialist access
with a single driver, question management access.
Use an
All employees
group, either a standard one or your own custom option.
Are there any leader groups that you need to exclude from accessing their Peakon dashboard as a leader?
Disable the group directly in its editing panel to deactivate it, and stop its members from using its privileges. You can re-enable it later.
Do you need to create different levels of settings access for your managers?
Having all managers in 1 group with the same settings is a recommended approach. Peakon automatically adds managers to the
Managers
group if they manage employees or segments.
You can use the standard groups already in Peakon to customize settings for different access control groups, or create custom groups.
Which settings should only be accessible to administrators?
If you manage your survey and questions centrally, you should only enable these settings for administrators. To restrict certain functionalities, you must disable these settings in the relevant access control groups.
Do local administrators need to add and remove leaders from access control groups?
Link access groups to segments, enabling local administrators to add or remove leaders from access control groups.
How much do you want to restrict comments and comment information from leaders?
These settings can limit the information on comments:
  • Access comments in real-time
  • View comment managers
  • View comments by segment
If you disable these settings for managers and later enable them, they apply retroactively.
How do you need to notify your leaders of their access?
Leaders receive digest emails during live survey rounds, if their access control group is active and has settings enabled. You can also bulk notify leaders directly within the access control group.
Do you plan to enable the personal dashboard for survey participants?
Enable this setting in the standard Employees group or create a custom
Individual
type group, and enable it there.
Are there any features that you need to trial with a small group before releasing them to all leaders or employees?
Create a new access control group with the relevant settings, then add test group members. When done testing, remove the group and enable the functionality in the intended group.
Should results from all question sets be available for all access control groups?
Enable or disable question sets directly in each group.
What level of specialist access do you require for your leadership?
There are two types of specialist access:
  • Specialist company-wide and,
  • Specialist segment specific.
Specialist, company-wide access rights enable administrators to provide access to specialist users who require company-wide data for a particular driver (or combination of drivers). They can tailor which drivers, within one or multiple question sets, an access control group has access to.
When creating a new specialist access control group of this type, you can define which drivers, across different question sets, users of that group can view on their dashboards.
Example: Enable access to your Director of Learning and Development to the Growth driver for access to company-wide learning and growth goals.
Specialist, segment specific access rights enable administrators to provide segment-specific access that enables you to grant access for users to specific question sets, drivers, or segments that have direct relevance to their roles, along with organization-wide survey data.
Example: Enable access to your French regional D&I manager, who is also a line manager for a team, to view their team access in one context and see the D&I data for France only in a new access by segment context.

Recommendations

  • Keep the number of administrators to a minimum.
  • Enable comment access for all managers from the start.
  • Enable all question categories for all manager groups.
  • Disable the notifications that you don’t want managers to receive.
  • Enable specialist access for users that need company level access for a single driver.

Requirements

No impact.

Limitations

Managed employees
type access control groups administer the settings managers can use within their managed area. To add someone to this type of group, you must make them a manager first, either by assigning a reporting line or a managed segment.
If a leader is part of 2 equal level groups, the settings in the 2 groups are equally binding. Example: 2
Managed employees
groups. When you disable a setting in 1 such group, but enable the setting in the other group, Peakon considers the setting enabled for overlapping leaders.
The sensitive comments setting displays relevant comments in an additional tab, as well as the general comments area. Disabling this setting won’t remove sensitive comments from the comments view for a leader.
Disabling access to restricted attributes will only hide the segments for leaders who don’t manage the segment or the hierarchy the segment is part of.
If you initially disable access to view comments for leaders, then enable it later, leaders can view historical comments if their dashboard has historical survey data.
Specialist access groups automatically provide access to the company level dashboard with the enabled driver. Enabling the open-ended comments setting for a specialist access user means they can view all open-ended comments, because they aren’t linked to a driver.
Values questions are part of the Engagement set, so it isn’t possible to give general or specialist access to Values questions without Engagement questions.
A change in permissions doesn't trigger a notification to the affected user, except if you add or remove them from the main Administrators group.

Tenant Setup

Navigate to the
Access Control
section on the
Administration
menu to view the available settings.
You can configure your access control settings before importing employee data, and update the settings at any time.

Security

Leaders of
Managed employees
groups only have access to their assigned areas. Leaders from
All employees
groups have company level access. It’s important to keep the number of such employees to a minimum, and also to stay up to date with updating employee records, specifically separation dates. As a result, Peakon can remove separated employees from the group after separation.

Business Processes

No impact.

Reporting

You can track sign-ins to Peakon manager dashboards using the
Manager behavior
usage metrics. Additionally, each access control group displays how recently each manager was active. It’s possible to export groups members by filtering on their last activity date.

Integrations

You can use an integration to add or remove employees in groups that populate through segments. Once the integration populates the segment with employees, Peakon automatically adds them to the linked access control group. Note that if it's a
Managed employees
group, the employee must first have a reporting line or a managed segment.

Connections and Touchpoints

Workday offers a Touchpoints Kit with resources to help you understand configuration relationships in your tenant. Learn more about the Workday Touchpoints Kit on Workday Community.