You can create or delete a security profile to manage metadata security in Anaplan Financial Consolidation. 

To create a security profile: 

  1. Go to the Security module. 
  2. In the Security Profile Access tab, select Add Profile to create a new profile.
  3. Enter the profile name in the Profile Name dialog, then select OK
  4. In the Hierarchies pane on the left, select Add Hierarchy.
  5. The Manage included hierarchies pane displays ‌a list of available dimensions. Select one or more hierarchies from each dimension.

Note: You do not need to select a hierarchy for each dimension. Only include the dimensions where access needs to be restricted according to your desired security policy. For example, if you wish to restrict access to the Entities dimension based on role, then include the relevant hierarchies from the Entity dimension. If you omit a hierarchy from the security profile, all roles have full access to it.


When you add a dimension, such as Account, the default hierarchy appears. You can add existing alternate hierarchies to a security profile to give users different views of the data. 


  1. When you have finished selecting the hierarchies, select the Select button to continue.
  2. Select the first dimension/hierarchy combination to assign roles. These grant or explicitly deny access to members of this hierarchy.
  3. Select the Add roles button in the Roles pane in the center of the editor. The Manage included roles pane displays with a list of available roles.
  4. Select the roles to include in the security profile.

Note: You don't need to set ‌access for all roles. If one or more roles are set for a specific hierarchy, then any roles that aren't set imply that those roles will have no access. Sometimes this is intentional. For example, if you have a role set up to manage workflows and this role doesn't require access to data, then you don't need to set access for this role.

  1. When you have finished selecting the roles, select the Select button to continue.
  2. Select the first role. You will now assign data access for this role to this hierarchy.
  3. Select the Manage members button from the Members pane on the right.
  4. If you know the exact member to set, you may use the search bar to find it. Otherwise, traverse the hierarchy tree by selecting the chevrons next to the parent members.
  5. Select the member to set the access rule. By default, the access rule will be set to INCLUDE Self And Descendants.
  6. To change the access rule, select from the drop-down list beside Self and Descendants
  7. Select whether you want to include this member or exclude this member, along with the relationship. For the Relationship field, select one an option:
OptionDescriptionExample
Self and DescendantsSelected member and all its descendants.

Europe (Self and Descendants) would include:

  • Europe
    • Spain
      • Madrid
      • Barcelona
    • France
      • Paris
      • Marseille
Self and ChildrenSelected member and its immediate children, but not the children of its immediate children

Europe (Self and Children) would include:

  • Europe
    • Spain
    • France
SelfSelected member only, no children.

Europe (Self) would include:

  • Europe
ChildrenChildren of the selected member, but not the children of its immediate children.

Europe (Self and Descendants) would include:

  • Spain
  • France
DescendantsAll the descendants of the selected member.

Europe (Descendants) would include:

  • Spain
    • Madrid
    • Barcelona
  • France
    • Paris
    • Marseille
  1. When you have finished setting the member access rules, choose the Select button to continue.
  2. Select Save on the toolbar to save the changes.

Repeat steps 9–20 to continue adding access for different hierarchies and roles as needed.

Note: When adding access rules, the last rule takes precedence. By adding rule details in the correct order, you can set granular access. For example, you can first add access to all of the USA entities but then restrict access to one or two entities below the USA, such as New York.

To delete a previously saved security profile: 

  1. Go to the Security module and select the Security Profile Access tab.
  2. If you saved more than one security profile, select the dropdown next to the profile name and choose a profile to delete. 
  3. Next to the name of the profile, select the ellipsis and choose Delete.
  4. Select Delete to confirm the deletion of the security profile. 

Warning: Once you delete a security profile, it can’t be recovered. All of the selected roles, hierarchies, and members that have been defined will no longer be selected.