ITS

System Access Review

Georgia Southern regularly reviews access to its sensitive systems. System Access Review, a semi-annual audit, is conducted in order to remain in compliance with the University System of Georgia’s Data Access Policy (USG IT Handbook, 9.4.1). In keeping with this policy, ITS performs System Access Review for Banner, PeopleSoft Financials, and Touchnet. Keep reading to learn more about how to complete this process.

For instructions on how to complete the System Access Review, please click here.

Frequently Asked Questions

General
  • Make sure to use Internet Explorer 11 to access the review.
  • Do not use a MAC to access the review.

Who do I contact if I have questions or need assistance?

Our MyTech Support representatives are happy to help you complete this process. Please contact us by calling (912) 478-2287 or by using any of our other contact methods.

How do I access the Review Site?

  1. In Internet Explorer, navigate to the System Access Review Site and click “My Pending Employees.”
  2. Review access for Pending Employees in each table, selecting “approve” or “deny” according the access levels needed.
  3. Click “Save” under the links menu to save your work.
  4. Review your work on the “My Completed Employees” screen.

What is a class?

A class is a set of rules that provide access to certain information. This could include access to names, birth dates, Social Security Numbers, etc. The description field for each class gives a general description of what kind of access the class provides.

How do I remove access to a class?

This is done automatically when you select the deny option for the employee. An automatic email will be generated to Accounts Management to remove the specific class from the employee.

How do I confirm I’ve completed my review of all my employees?

Click on ‘My Completed Employees’ under the ‘Links’ menu on the right side of the form

One (or more) of my employees is not in my review list.

The supervisor information is pulled from OneUSG. To request a supervisor change, please enter a MyTech Help ticket with the following information:

Subject: System Access Review – Supervisor Change

In the Description of Issue field – please include

Employee Name
Employee ID
New Supervisor Name
New Supervisor Employee ID

One (or more) of the employees in my list are not under my supervision.

The supervisor information is pulled from OneUSG. To request a supervisor change, please enter a MyTech Help ticket with the following information:

Subject: System Access Review – Supervisor Change

In the Description of Issue field – please include

Employee Name
Employee ID
New Supervisor Name
New Supervisor Employee ID

Do I have to complete this in one sitting?

No, you will have 30 days to complete the review.

I have an employee that I supervise who approves timecards. However, they are not listed.

This review only covers employees who access the system directly (such as PPGRA, payroll, or HR), not to eTime. Employees who review or approve time will not show up in this review.

Banner

My employee shows as having Banner classes but the employment status shows the employee is terminated, what do I do?

Because the information pulled from Banner is a snapshot in time the information shown may not be in the same state as it is today. You still must review all access that shows for your employee. If that access is correct then mark it as approved, if it is not correct then mark it as denied.


What happens if I remove the ALL_BAN_USERS class?

By removing this class from the user, the user will no longer be able to access Banner, AppsXtender, or Business Objects.


What happens if I remove the GSU_JOBSUB_C class?

By removing this class from the user, the user will no longer be able to run or print from Banner Job Submissions.

What if a class is removed by mistake?

If you have not completed the review, go back to the row and change Denied to Approved.

If you have hit complete, follow the steps below or download our more detailed instructions to complete Editing Completed Employees in System Access Review:

  1. From the System Access Review home screen, click “My Completed Employees” in the links menu.
  2. On the “My Completed Employees” screen, click the row you wish to edit, then select the “Edit Item” button in the toolbar.
  3. In the edit screen, edit the “Access Status” field and then click “Save.”
  4. Be sure to check your work on the “My Completed Employees” screen.

Download Instructions

Banner Account Status – what does this mean?

Each employee has an account status in Banner. Most accounts will have an OPEN status, meaning that the account is open and is usable. There are a few other status that may show up beside an employee. This is the state of the account in Banner at the time the information was pulled. All of these statuses still mean the account has access to Banner through the listed classes so they still need to be reviewed. Below is a list of the status and their respective definitions.

  • OPEN – The Banner account is open and able to be used for listed classes
  • EXPIRED – The password expired and the grace period is over.
  • EXPIRED(GRACE) – The password expired but still within grace period.
  • LOCKED(TIMED) – Too many attempts with incorrect password.
  • EXPIRED & LOCKED(TIMED) – Combination of the above.
  • EXPIRED(GRACE) & LOCKED(TIMED) – Combination of the above.
  • EXPIRED & LOCKED – Expired password and the account is disabled but still has Banner classes assigned to account.
  • EXPIRED(GRACE) & LOCKED – Expired password and the account is disabled but still has Banner classes assigned to account.


Who do I contact if I have questions or need assistance?

Completing System Access Review can be complicated. Our MyTech Support representatives are happy to help you complete this process. Please contact us by calling (912) 478-2287 or by using any of our other contact methods.
PeopleSoft/ePro

One of my employees only has the “BOR PeopleSoft User” class, but they do not access PeopleSoft or ePro.

Users were given the “BOR PeopleSoft User” class in order to be added as a Budget Manager. This is the only role required and is requested on behalf of the department by Financial Accounting. If this employee’s job function no longer request them to be a Budget Manager, mark the Access Status as denied.

I see more roles than I requested. Why is that?

When requesting ePro “Requester” or ePro “Approver” access, there is a set group of classes that are needed. Some classes are required for both “Requesters” and “Approvers”. Each class is only added once.

For Requesters

  • BOR PeopleSoft User
  • BOR_AD_HOC_APPROVE
  • BOR_CAT_Requester
  • BOR_EP_INQUIRY
  • BOR_EP_MAINT_REQ_SCI_YE_CUTOFF
  • BOR_EP_REQUESTER
  • BOR_PO_RECV_EPRO

For Approvers

  • BOR PeopleSoft User
  • BOR_AD_HOC_APPROVE
  • BOR_CAT_Requester
  • BOR_EP_INQUIRY
  • BOR_EP_MAINT_REQ_SCI_YE_CUTOFF
  • BOR_EP_RA_CHANGEDISTR
  • BOR_EP_RA_CHANGEHDR
  • BOR_EP_RA_CHANGELINE
  • BOR_EP_REQ_APPROVE

Who do I contact if I have a question/problem with PeopleSoft/ePro?

Contact VPBF – IT at bfaccounts@georgiasouthern.edu

Last updated: 6/6/2019

ITS Accounts • PO Box 8136 Statesboro, GA 30460 • accounts@georgiasouthern.edu