Application Processing Module Security
The
Application Processing Module provides several security mechanisms to protect the system from unauthenticated access and limit user access depending on assigned groups. Security administrators use the
FICO Application Studio Designer to create roles and use the
Application Processing Module to create groups and assign them to users.
Keep your data safe using the following techniques:
- Limit access to the Application Processing Module by requiring passwords.
- Limit access to particular Application Processing Module features and tasks through assignment of roles.
- Maintain an audit trail to capture activities that need to be reviewed by security personnel.
![]() | Note: Confidential fields in the preconfigured
Application Processing Module UI are masked at the template level (for example, at the OM APM Consumer template level, or the OM APM Small Business template level). Users with the proper permissions are able to view confidential information (such as a customer’s full social security number).
|
For any items that administrators can edit, such as roles, users, and groups, changes are effective immediately.
Related Information
- Covered Topics
- Security Overview
FICO Origination Manager uses a built-in security system to ensure that only authorized users can access the system. Authentication uses the external LDAP system that is configured in the Application Processing Module. - Managing Roles
The roles defined for a user are the combination of the roles the user is explicitly assigned and the roles assigned to the groups to which the user belongs. - Available Roles and Permissions
When setting up the Application Processing Module, you must create users and assign specific roles to those users based on the tasks they need to perform. - Managing Users
Administrators with the proper permissions use the Application Processing Module user management pages to create and modify users and assign roles and groups to them. - Managing Groups
Administrators with the proper permissions can create, edit, and assign roles to groups (which are also referred to asuser groups
). - Managing Clients
Administrators with the ManageClients role use the Application Processing Module client management page to create and modify clients. Clients are organizations, such as a financial institution or an insurance company that can set up business policy rules and application processing parameters to process loan applications. - Unlocking Applications
Administrators with the proper permissions can release locked applications when write access to a locked application is immediately required and the user cannot be contacted. - Disabling the Administrator Account
When the Application Processing Module is installed, an account with the user nameadmin
and passwordadmin
is created. This account is used to perform the initial setup of users in the system. For security reasons, it is recommended that you disable the account after completing the setup.