User Privileges and Limit Groups for DRO
A plain-language guide to the access controls and spending guardrails in the DRO (IAS 37) module: the privileges that decide who can do what, the levels each privilege is granted at, and the limit groups that cap how much a plan change can move.
In this article
- Where privileges and limit groups are configured
- DRO privileges
- Privilege levels
- DRO privileges on the admin side
- Limit groups
- Limits at the person level
- Matching privileges and limits to responsibility
Where privileges and limit groups are configured
DRO includes its own access controls and its own spending guardrails. Privileges determine which actions a user can perform, and limit groups cap the size of a plan change. Both are configured in the admin settings, so this is administrator territory.
DRO privileges
DRO privileges are granted at the module level. There is no separate control for asset versus expense, so a DRO privilege applies to both subtypes.
The DRO privileges appear when the filter is set to Finance. They are grouped together under a DRO Plan node, and there are seven of them:
-
DRO Approved Plan Import and DRO Historical Plan Import, for bringing plans into the system
-
DRO Plan (Above AOC), for planning at a roll up level
-
DRO Plan Form
-
DRO Plan Roll Forward
-
DRO Plan Snapshot
-
DRO Plan by Expense Type
Grant each privilege only to the users who require it.
Privilege levels
Each privilege is granted at up to four levels, shown as the columns across the screen: Report, View, Modify, and Add/Delete. For any given privilege, the level determines not only whether a user has access, but the extent of that access.
A reviewer might be given Report and View on the import privileges, while Modify and Add/Delete remain with the plan owner. Each level should match the user's responsibilities.
DRO privileges on the admin side
A second set of DRO privileges sits under the Admin filter. These govern setup and versioning, and there are three of them:
-
DRO Plan Adjustment Settings
-
DRO Plan Admin
-
DRO Plan Version Schedule
They are intended for the administrators who configure the module itself.
Limit groups
DRO adds two new limit group categories: New Planning DRO, which governs new plans, and Modify Planning DRO, which governs changes to existing plans.
The important detail is how the limit is measured. The limit applies against the total net adjustment. It is the net movement of a plan change that is evaluated against the limit, not the gross costs alone.
Limits at the person level
Limits also appear at the person level on the plan itself. A plan’s Contacts list shows each contact with a role, for example Initiator, along with their approval limit. This provides a plan-by-plan view of the participants and the approval authority each holds.
Matching privileges and limits to responsibility
Privileges should match each person’s real responsibility, and limit groups should match the customer’s approval policy. Once both are set, the module enforces them automatically.
Related articles
What DRO is and why customers use it
Core DRO concepts and terminology
Choosing the Asset or Expense subtype
Creating your first DRO plan