QUESTION: Do I need more security than administrator to do what I need? Does an admin person need security?
RESPONSE: Granted administrator rights does not extend to all functional rights. Functional rights must be separately granted within the user's assigned security profile.
The administrator security rights are designed to grant the designated user the ability to manage security profiles. As a result, we continue to remove implied security from the administrator profile to separate functional security from the right to administer security profiles - separating the two. To have access to any option that triggers a security message, the referenced security item must be added to the security group to which you or any other administrator is assigned to.
From a best practice perspective, firms where the person responsible for security has other functions, it is recommended to create a second member and user. This second user would have administrator rights but no additional security other than to member properties. The other member and user would be used regularly to complete daily tasks. Alternatively, if only one user is created, we recommend that be assigned to a membership in a user group in context of the member’s responsibility center, limiting the security to ensure daily work is not executed without internal controls. Security for not often used options can be taken and removed on an as need basis.