Access Method Profiles

Access Method Profiles define what a person sees on their Home page. Organizations can change a user's Role Profile based on different criteria. Define the components that a user can access from different locations, corporate or personal devices, or from the mobile app. You do this by mapping a Role Profile to access method types (Known IP, Mobile Device or Workforce Mobile) and corresponding access method values.

Note:
  • Access Method Profiles extend the capabilities of Known IP Addresses, which are tenant-wide, to the user level.
  • When an employee logs in to the system, a Role Profile is assigned based on the employee's Access Method Profile.
  • When a manager with multiple roles logs in to the system, the default Role Profile is assigned based on the Access Method Profile, but the Function Access Profile and Display Profile change when the manager changes role.
  • If you are using Delegation Authority, the default Role Profile is based on the Access Method Profile that is assigned; it changes when the Delegation Profile changes.

Example Access Method Profiles for a manager

A manager could access all manager functions while at work, including editing the schedule, responding to requests, and creating reports, but only limited functions while at home such as view the schedule but not edit it and view employee requests but not approve or reject them. To configure this example, you can do the following:

  1. On the Known IP Address page, define an IP address for the work site called WorkIP.
  2. On the Role Profiles page, define a Role Profile called Manager-work for the manager's work-site activities and another Role Profile called Manager-home for the manager's home activities.
  3. On the Access Method Profiles page, create a profile that maps access method types and values to the two Role Profiles:

    Access Method Type

    Access Method Values

    Role Profile

    Known IP

    WorkIP

    Manager-work

    Known IP

    All Unknown IPs

    Manager-home

Similarly, you can limit the manager's mobile access to corporate devices by creating an Access Method Profile with the following characteristics:

Access Method Type

Access Method Values

Role Profile

Mobile Device

Corporate

Manager-work

Mobile Device

Personal

Manager-NoAccess

Create Access Method Profiles

To create an Access Method Profile:

  1. From the Main Menu, select Administration > Application Setup > Common Setup > Access Method Profiles.
  2. On the Application Method Profiles page, click tap Create .
  3. On the Create Access Method Profiles page, enter a name and description, and click tap Create .
  4. Complete the following:
    1. Access Method Type— Select from the following:

      Known IP— Restrict access to a Known IP Address.

      Mobile Device— Restrict access to a corporate or personal mobile device.

      Mobile App— Restrict access to the UKG Pro Workforce Management mobile application.

      Punch Status— Restrict access based on whether the employee is punched in or punched out.

    2. Access Method Value— Depending on the Access Method Type selected, provide the following information.

      Access Method Type

      Access Method Value

      Known IP

      Depending on the IP addresses configured on the Known IP Address page, select from the following:

      • All Known IP Addresses
      • All Unknown IP Addresses
      • A listed IP address

      Mobile Device

      Depending on the user's type of mobile device, select from the following:

      • Corporate
      • Personal
      Note: Corporate Devices are owned by your organization compared to Personal Devices that are owned by individual employees. Corporate Devices are configured by an Enterprise Mobility Management (EMM) provider. Refer to the EMM topics in the online help for more information ( Administration > Mobile App > EMM > Managed App Configuration).

      Mobile App

      Depending on whether the user is accessing the system from the UKG Pro Workforce Management mobile application:

      • Yes
      • No

      Punch Status

      Select one of the following:

      • In— The employee is punched in and has access only when on-premises.
      • Out— The employee is punched out and can access when off-premises.
    3. Role Profiles— Select a Role Profile that has been defined for your organization.
    4. Click Tap Save.
  5. To change entries in the table, select an entry and click tap Edit , and to delete an entry, select an entry and click tap Delete .
  6. When using multiple mappings, select a row and use Increase Priority and Decrease Priority to define the precedence of the mappings.
  7. Click Tap Save.

Edit or duplicate Access Method Profiles

  1. From the Main Menu, select Administration > Application Setup > Common Setup > Access Method Profiles.
  2. On the Application Method Profiles page, click tap Edit .
  3. On the Edit page, select one of the following:
    • To edit the existing profile, select Save changes everywhere that the named entity is used
    • To duplicate the profile or create a new profile based on the selected profile, select Save as a new named entity.
  4. As necessary, change the name and description and modify the Access Method Profile Mapping table as described in Create Access Method Profiles.
  5. Click Tap Save.

Delete Access Method Profiles

  1. From the Main Menu, select Administration > Application Setup > Common Setup > Access Method Profiles.
  2. On the Application Method Profiles page, select a profile and click tap Delete .

Assign Access Method Profiles

You assign Access Method Profiles in the People Information component.

  1. From the Main Menu, select Maintenance > People Information.

  2. From the People Information page, select a person from the list and from the Employee section, expand Access Profiles.

  3. From the Access Method Profile drop-down list, select a profile.

  4. Click Tap Save.

Note: Users can be assigned only one Access Method Profile.