Full Access Permission Lists
This report identifies PeopleSoft permission lists that have an unusually high number of menu authorizations.
This report identifies PeopleSoft permission lists that have an unusually high number of menu authorizations.
This report identifies active PeopleSoft message nodes that have no authentication configured or have authentication enabled but no passwords set.
How PeopleSoft security administrators use psLens to audit access, run security reports, and manage permission lists, roles, and users.
This alert finds queued or scheduled Process Scheduler requests where the submitting operator’s account (OPRID) is currently locked in PSOPRDEFN (A…
This report identifies unlocked PeopleSoft user accounts whose passwords have not been changed within a configurable number of days.
This report generates a consolidated view of everything a single PeopleSoft user can access.
Why granting App Designer access for metadata research creates unnecessary risk, and how psLens provides a safer alternative with read-only browsing.
This report identifies permission lists that grant access to dangerous capabilities in PeopleSoft.
The objects, roles, and Integration Broker setup the SWS framework adds to a PeopleSoft environment. Written for the admin, DBA, or security reviewer who has to approve the install.
‘SOAP to CI’ is a powerful tool that allows using excel or any web client to interact with PeopleSoft Component Interfaces via SOAP web services.
This page documents the SSO Bypass Password Audit report, which identifies native PeopleSoft user passwords stored in the PSOPRDEFN table.
Special PeopleTools access (Application Designer, Data Mover, Object Security, Query, Import Manager, 2-Tier Client) is granted on the PeopleTools …
What code runs in psLens, how it’s built and distributed, dependency posture, and the vulnerability disclosure & patching process.
This alert finds PeopleSoft users with excessive failed login attempts by querying the PSPTLOGINAUDIT table.
Permission lists (PSCLASSDEFN, sometimes called classes) are the lowest-level grantable security object.
How users log in to psLens, the deliberate scope decision behind no in-app RBAC, SSO via reverse proxy today, and native SSO on the roadmap.
Roles (PSROLEDEFN) are named bundles of permission lists. Users get roles, not permission lists directly.
What psLens stores, what it does not, how data is encrypted at rest and in transit, and what gets logged for audit.
Users (PSOPRDEFN, historically called operators) are login accounts.
How psLens is deployed, network requirements, sizing, backup, upgrade, DR, monitoring — consolidated for ops and security reviewers.
SOC 2 posture, GDPR / personal-data handling, DPA, sub-processors, business continuity, and how psLens fits in a vendor-risk review.
PeopleSoft service operation access is granted by permission list (PSAUTHWS) and rides roles out to users. A single broadly-held role can expose a web service to hundreds of accounts. How to trace the chain, the gotchas that undercount it, and a faster way.
Most PeopleSoft environments have active message nodes with no authentication configured (AUTHOPTN=‘N’). How to check PSMSGNODEDEFN, why it matters, and what to fix first.
How to trace PeopleSoft component access through PSAUTHITEM, PSROLECLASS, and PSROLEUSER — the query, the four mistakes that produce wrong answers, and a faster way.