Use this page for questions and troubleshooting related to managing users, assigning roles, configuring entity access, account access, and cost center access in Yarken.
Understanding the Yarken access model
Q: How does the Yarken access model work? What are the layers of access control?
A: Yarken uses a three-layer access model that determines what a user can see and do across the platform:
|
Layer |
What it controls |
Applies to |
|---|---|---|
|
Roles |
Which platform menus, features, and actions are available |
All users |
|
Entity Access |
Which organizational entities (and their associated data) are visible |
Non-admin users only |
|
Account & Cost Center Access |
Which financial accounts and cost centers are visible in dashboards, reports, and planning |
Non-admin users only |
All three layers must be configured correctly for a user to see the right data. A user with a role but no entity, account, or cost center assignment may see empty dashboards or encounter access errors.
Q: Do Admin users need entity, account, or cost center access assigned?
A: No. Admin users have full visibility across all entities, accounts, and cost centers by default. Entity access, account access, and cost center access configuration applies only to non-admin users.
Q: Does Ask Yarken respect all three access layers?
A: Yes. Ask Yarken is permission-aware and respects role-based access, entity access, account access, and cost center access controls. Users only receive answers, charts, summaries, and recommendations based on data they are authorized to view. If a user does not have access to a data area, Ask Yarken does not expose it.
Roles and permissions
Q: What roles are available in Yarken and what does each one control?
A: Yarken provides six core roles and four specialized roles:
Core roles:
|
Role |
Home |
Reports |
Analytics |
Planning |
Chargeback |
Admin |
|---|---|---|---|---|---|---|
|
Admin |
✅ |
✅ |
✅ |
✅ |
✅ |
✅ |
|
Cost Model Manager |
✅ |
✅ |
✅ |
✅ |
✅ |
Partial* |
|
Power User |
✅ |
✅ |
✅ |
Partial** |
✅ |
❌ |
|
Viewer |
✅ |
Read-only |
❌ |
❌ |
❌ |
❌ |
|
Dashboard Only |
✅ |
❌ |
❌ |
❌ |
❌ |
❌ |
|
No Role |
❌ |
❌ |
❌ |
❌ |
❌ |
❌ |
*Cost Model Manager has access to all Admin functions except User Management (cannot add, manage, or deactivate users, or assign access permissions).
**Planning (Partial): Power Users can access Planning → Business Case only. Budget, Forecast, and Cloud Forecast require additional specialized roles.
Specialized roles (must be combined with a core role):
|
Role |
Purpose |
|---|---|
|
Budget Contributor |
Review and submit assigned budget/forecast items |
|
Budget Process Owner |
Create, manage, approve, and publish budgets/forecasts |
|
Chargeback Approver |
Review and approve monthly chargebacks |
|
Cloud Engineer / Cloud Cost Owner |
Manage cloud forecasting at team or org level |
Q: Can I assign multiple roles to a single user?
A: Yes. Roles are not mutually exclusive. You can combine multiple roles to match a user's access needs. Common combinations include:
Q: What is the difference between a Power User and a Viewer?
A: Key differences:
|
Capability |
Power User |
Viewer |
|---|---|---|
|
Home dashboards |
✅ Full access |
✅ Full access |
|
Reports |
✅ Full access |
✅ Read-only |
|
Analytics |
✅ Full access |
❌ No access |
|
Business Case (Planning) |
✅ Full access |
❌ No access |
|
Chargeback |
✅ Full access |
❌ No access |
|
Custom dashboards |
✅ Full access |
✅ Read-only |
|
Admin menu |
❌ No access |
❌ No access |
Q: What is the Dashboard Only role and when should I use it?
A: Dashboard Only provides restricted, view-only access to the Home page. Users can view the assigned default dashboard (custom or standard), apply filters, and drill down — but cannot access Reports, Analytics, Planning, Chargeback, or Admin.
Use this role for:
-
Executive stakeholders who need a single dashboard view
-
External partners who need limited visibility
-
Temporary access before assigning a broader role
Q: What is the "No Role" option and how is it used?
A: No Role is a placeholder that allows administrators to create user accounts without immediately granting platform access. Users with No Role cannot see any dashboards, reports, analytics, or functional features.
Use No Role when:
-
Pre-loading users into the system before access decisions are finalized
-
Uploading users via CSV without specifying a role (system auto-assigns No Role)
-
Staging onboarding — create accounts first, assign roles later
Q: What is the Cost Model Manager role and how does it differ from Admin?
A: Cost Model Manager provides the same access as Admin for cost model management — including Designer, models, settings, data uploads, rules, allocations, and configurations — but cannot perform user management tasks.
Managing users
Q: Can I edit a user?
A: Yes. Admin users can edit existing user details from Admin → User Management → Users. Changes to roles and access settings user to sign out and sign back in.
Q: Can I delete a user from Yarken?
A: Yes, but only if the user has not contributed to any data or reports. Yarken prevents deletion of users who have historical contributions to protect data integrity and audit records.
Q: Can I add users in bulk?
A: Yes. Admin users can add multiple users at once by using the upload option. Download the CSV template, enter each user’s details such as name, email, role, default dashboard, and active status, then upload the completed file. Yarken validates the file before import and flags any missing or invalid values so they can be corrected. If a role is not provided, the user is typically created with No Role and can be updated later.
Entity access
Q: What is entity access and why is it important?
A: Entity access controls which organizational entities a non-admin user can view and work with. Entities represent business units, regions, legal entities, or operating divisions.
Q: Can a user be assigned to multiple entities?
A: Yes. Non-admin users can be assigned to one or more entities. The user can view and filter by all assigned entities across dashboards, reports, analytics, planning, and Cost Explorer.
Q: What is the Default entity?
A: Every Yarken environment includes a Default entity. The Default entity:
-
Always exists and cannot be deleted
-
Can be renamed
-
Is automatically assigned to spend, cloud, and planning records when no entity is specified
-
Ensures backward compatibility for environments that don't use multi-entity
If your organization operates with a single entity, the Default entity handles all data. If you later expand to multiple entities, the Default entity continues to hold any unscoped records.
Q: Can I delete an entity?
A: Yes, but only if no dependent records exist. Before deleting, ensure:
-
No spend records reference the entity
-
No budgets or forecasts are assigned to the entity
-
No users are assigned to the entity
-
No upload rules depend on the entity
If dependent records exist, reassign them to another entity before deleting. The Default entity cannot be deleted (but its name and attributes can be updated).
Account access
Q: What is account access?
A: Account access controls which financial accounts a non-admin user can view and manage within Yarken. By assigning specific accounts to a user, you ensure they can access only the data relevant to those accounts across dashboards, reports, and planning views.
Key behaviors:
-
Each user can be assigned one or more accounts
-
Users can view and analyze only data associated with their assigned accounts
To access data effectively, users must be granted both Account Access and Cost Center Access.
Q: What happens if a user has a role and entity access but no account access?
A: The user can authenticate and access the platform menus (based on their role), but dashboards and reports may show empty or incomplete data because account-level filtering hides all financial data that is not associated with an assigned account.
Q: Are account access assignments linked to entities?
A: Account access and entity access are configured independently. However, if specific accounts are used within specific entities, the combined effect of entity access + account access determines what the user sees.
Cost center access
Q: What is cost center access?
A: Cost center access controls which cost centers a non-admin user can view and manage within Yarken. By assigning cost centers to specific users — typically Cost Center Owners — you ensure users can access only the data relevant to their responsibilities.
Key behaviors:
-
Each user can be assigned one or more cost centers
-
Users can view and analyze only data associated with their assigned cost centers
-
Assigned users can access cost center budgets, forecasts, and related planning, reporting, and analytics data
Q: Why is cost center access important for Planning?
A: In the budgeting and forecasting workflow, Budget Contributors review and submit budgets for their assigned cost centers. Cost center access determines:
-
Which cost center budgets and forecasts appear in Planning → Cost Centre Budgets & Forecasts
-
Which cost center data is visible in dashboards and reports
-
Which workforce planning entries the contributor can review
Without assigned cost centers, Budget Contributors cannot see any planning data for review.
Q: Do users need both account access and cost center access?
A: Yes. To access data effectively, users must be granted both Account Access and Cost Center Access. These work together:
Troubleshooting user management, roles & access issues
User sees "No entities assigned to you" error at login
Cause: The non-admin user does not have any entities assigned, or an intermittent validation issue is preventing entity recognition during sign-in.
Resolution:
-
Navigate to Admin → User Management → Entity Access
-
Select the user and verify that at least one entity (including the Default entity) appears in Assigned Entities
-
If entities are assigned but the error persists, ask the user to clear browser cache and sign in again
User has Viewer role but can only see the Home screen — no report data visible
Cause: The Viewer role grants read-only access to Home and Reports, but the user may be missing entity access, account access, or cost center access, causing dashboards and reports to display empty.
Resolution:
-
Verify the user has at least one entity assigned in Admin → User Management → Entity Access
-
Verify the user has accounts assigned in Admin → User Management → Account Access
-
Verify the user has cost centers assigned in Admin → User Management → Cost Center Access
-
If all three access layers are configured, check that the assigned entities/accounts/cost centers contain data for the selected financial year and model
User cannot access Budget or Forecast in Planning
Cause: The user has a core role (e.g., Power User) but does not have the specialized Budget Contributor or Budget Process Owner role required for Budget and Forecast access. Power User alone provides access only to Planning → Business Case.
Resolution:
-
Navigate to Admin → User Management → Users
-
Edit the user and add the appropriate specialized role:
-
Budget Process Owner — to create, manage, and approve budgets/forecasts
-
Budget Contributor — to review and submit assigned budget/forecast items
-
-
Click SAVE
-
Verify the user also has the correct cost center access for the budgets they need to work with
User deletion fails — "user has contributed to data or reports"
Cause: Yarken prevents deletion of users who have historical contributions to protect data integrity and audit records.
Resolution:
-
Navigate to Admin → User Management → Users
-
Locate the user and click Edit
-
Set Active = No to deactivate the user
-
Click SAVE
The user can no longer sign in, but all historical contributions, data ownership, and audit records remain intact. The account can be reactivated later if needed.
Account or cost center access changes not reflecting in dashboards
Cause: Access changes take effect immediately, but the user's browser session may be using cached data or the user may not have refreshed.
Resolution:
-
Ask the user to sign out and sign back in
-
Clear browser cache if the issue persists
-
Verify the changes were saved successfully in Admin → User Management → Account Access or Cost Center Access
-
If the user is viewing Analytics, a cube refresh may be needed for the access changes to take full effect
Related content