Source: https://vaultcrmhelp.veeva.com/doc/Content/CRM_topics/Align/Configuration/SecurityTree.htm

## Align Security Tree Management

Align can now maintain a Security Tree in Vault CRM using a structure that mirrors the territory hierarchy within Align. Security Trees are a Vault Platform capability that enable customers to configure their own hierarchical security mechanism. While territory assignment controls access to accounts, the Align Security Tree controls record-level access to other objects that are relevant to a user's job, for example Time off Territory, Coaching Reports, or Multichannel Cycle Plans. This ensures that users have access to only those records that relate to themself or their subordinates.

For example, a cardiology end user assigned to the UK\_CARDIO\_SOUTH\_LONDON territory is also assigned to the UK\_CARDIO\_SOUTH\_LONDON Security Tree node, which controls access to the records related to that user or others assigned to the same node. Her district manager, assigned to the UK\_CARDIO\_SOUTH territory and Security Tree node, has access to the records secured by that node and by the nodes beneath it in the tree.

Align assigns each user to a single Align Security Tree node. Vault then uses User Reference Assignment to automatically assign records to the correct node based on a specified User field (typically the Owner field). Customers can choose which objects use this security model.

**Who can use this feature?**

* Align Operational Users - Browser
* [Defining Objects Controlled by the Align Security Tree](#Defining)
* [Maintaining the Align Security Tree](#Maintain)
* Users require an Align License

### Configuring Align Security Tree Management for

[![Closed](../../../../Skins/Default/Stylesheets/Images/transparent.gif)Integration Users](#)

To configure this feature:

1. Ensure the following features are configured:

   * [Managing Users in Align](../UserMgmt/UserMgmt.htm)
   * [Configuring Territory Management](../../TerritoryManagement/Config.htm)
2. Navigate to **Admin > Users & Groups > Permission Sets**.
3. Select the appropriate **Permission Set**.
4. Select **Objects**.
5. Grant the following permissions:

   | Object | Object Permission | Object Types | Fields | Field Permission |
   | --- | --- | --- | --- | --- |
   | aln\_security\_tree\_node\_\_v | CRED | All | All | Edit |
   | aln\_territory\_\_v | CRED | All | crm\_security\_node\_\_v | Read |
   | aln\_security\_tree\_node\_c\_\_sys | CRED | All | All | Edit |
   | aln\_roster\_member\_\_v | CRE | All | crm\_security\_tree\_node\_override\_\_v | Edit |
   | All intersection security tables created for objects controlled by the Align Security Tree. See Security Tree Administration for more information. | CRED | All | All | Edit |

[![Closed](../../../../Skins/Default/Stylesheets/Images/transparent.gif)Align Operational Users](#)

To configure this feature:

1. Ensure the following features are configured:

   * [Managing Users in Align](../UserMgmt/UserMgmt.htm)
   * [Configuring Territory Management](../../TerritoryManagement/Config.htm)
2. Navigate to **Admin > Users & Groups > Permission Sets**.
3. Select the appropriate **Permission Set**.
4. Select **Objects**.
5. Grant the following permissions:

   | Object | Object Permission | Object Types | Fields | Field Permission |
   | --- | --- | --- | --- | --- |
   | aln\_roster\_member\_\_v | CRE | All | crm\_security\_tree\_node\_override\_\_v | Edit |
6. Navigate to **Admin > Configuration > Objects > aln\_roster\_member\_\_v > Layouts**.
7. Place the **crm\_security\_tree\_node\_override\_\_v** on the appropriate layouts.
8. Navigate to **Align > Align Admin > Align Settings (Production)**.
9. Edit the **Global Align Settings** record.
10. Select the **Security Tree** value for the Manage CRM Features multiselect picklist.

### Defining Objects Controlled by the Align Security Tree as

[![Closed](../../../../Skins/Default/Stylesheets/Images/transparent.gif)Align Operational Users](#)

Align Operational Users maintain the territory hierarchy and the roster member assignments in Align, and Align maintains the corresponding Security Tree in Vault CRM. To define which objects are controlled by the Align Security Tree:

1. Navigate to **Admin > Configuration > Objects**.
2. Select the appropriate object.
3. Select **Edit**.
4. Populate the following fields:

   * Security Tree Object – Select Align Security Tree Node
   * Tree Assignment Object Name – Enter the appropriate name
   * User Reference Assignment Field – Select the appropriate field used as the basis for tree node assignment. For example, owner\_\_v.
   * Restrict Users to a Single Node Assignment – Select this checkbox. This enables records to be auto-assigned to Align-managed Security Tree nodes.
5. Select **Save**.

See [Security Tree Administration](https://platform.veevavault.help/en/gr/828859/#configuring-security-tree) for more information.

### Maintaining the Align Security Tree as

[![Closed](../../../../Skins/Default/Stylesheets/Images/transparent.gif)Align Operational Users](#)

Nodes of the Align Security Tree are automatically created and maintained during [Pushes to CRM](AlignCRMIntegration.htm#Pushing2).

The root node is automatically generated during the first push after enabling this feature and must not be renamed.

Nodes are automatically created and arranged to mirror the Vault CRM instance’s territory hierarchy, and users are automatically assigned to the Align Security Tree node corresponding to their assigned territory.

If a Roster Member has multiple active territory assignments, Align operational users must ensure at least one of the following conditions are true in order to avoid a sync error:

* Ensure the roster member has exactly one Primary Territory defined
* Populate the crm\_security\_tree\_node\_override\_\_v field on the appropriate aln\_roster\_member\_\_v field with the appropriate node

Once assigned, users can access any record assigned to their node and, conversely, are prevented from accessing records assigned to other nodes. Users assigned to parent territories (for example, managers) can view all records assigned to their node, as well as any record assigned to descendent nodes.

#### Transfers in the Align Security Tree

When an end user transfers to a different territory, Align automatically reassigns records that they own to their new Security Tree Node. This enables the end user to continue to access data that they own, and also grants their new manager access to the transferred records.

### Related Topics

[Managing Users in Align](../UserMgmt/UserMgmt.htm)

[Security Tree Administration](https://platform.veevavault.help/en/gr/828859/#configuring-security-tree)

[Territory Management Overview](../../TerritoryManagement/Overview.htm)
