Easy Auditor Planning and Design
Introduction
This page covers Easy Auditor–specific planning considerations that are not part of the general User Roles reference. Currently this covers the built-in auditor account used for separation of duties.
Auditor built-in account
A separate built-in auditor local user account exists specifically to support separation of duties between Easy Auditor functions and other Eyeglass administration — a common requirement for compliance frameworks such as HIPAA and PCI. The EASY_AUDITOR_VIEW and EASY_AUDITOR_MODIFY permissions (see User Roles — Data Security Roles and Permissions) are the two permissions automatically assigned to this account.
If you need a role with only read-only or only read/write Easy Auditor access beyond what the built-in auditor account provides, create a custom role using the same two permissions and the standard RBAC workflow in the User Role Guide.
As with any built-in account, change the default password immediately after first login, before assigning the account to any user.
See also
- User Roles — Full Data Security role and permission reference.
- User Role Guide — Full Eyeglass RBAC setup: creating roles, assigning permissions, AD group mapping.