Unified Risk System
Within financial institutions, the Data Units or Information Systems areas develop reports and scorecards to facilitate user areas’ work. Once the reports are in production, a security and governance framework needs to be established that defines the permissions for access to them.
In this context, Bluetab is developing the information access model, determining the criteria for controlling access to the data:
- Access restriction. Establishing which users can access which reports (e.g. the Risks User can access the RDA Scorecard).
- Data restriction. Indicating, within a report, what data can be accessed (e.g. an office manager can only view the data for their office).

In this context, Bluetab is developing the security model for the reports of a leading Spanish financial institution by implementing two types of security levels, and enabling this to provide coverage to the various group entities:
- Access Security: managed through Catalogue Groups, as a method of organisation to which users can be assigned while giving access to the various scorecard elements. Therefore, these groups will allow a user or users to access a report, or not. Users are associated with a tool catalogue group with access to a particular set of reports.
- Data Security: managed through Application Roles, as a feature that enables control over what data a user or users assigned to the role can or cannot query. Therefore, these roles will allow, or not, a user to view detailed information on data at the customer or office level. However, users will always be able to view aggregated information.
This project has been carried out within the institution’s technological stack, implementing the security model in OBIEE.
SUCCESS STORIES