Submit Your Suggestions for Vista

Ideaspace topics with the most votes have been moved into the Suggestion Box. If there is a topic missing, please re-enter. Our product team reviews the Suggestion Box items regularly and will provide updates as to status and incorporation into upcoming releases.

need a method to secure EFT Files from AP and PR

Auditors have raised concerns that users creating and saving EFT files could potentially edit those files before transmitting them to the bank for processing. This is considered an unacceptable security risk and we need a more secure workflow.

We would like to remove control as to where an EFT file is created/saved from the user creating the file, and have it saved in a secure network location where only a security admin or someone responsible for transferring that file to the bank will have access. 

  • Andrew Karr
  • Mar 17 2017
  • Shipped
Company Oldcastle Materials Group
Job Title / Role PR Admin
I need it... Yesterday...Come on already
  • Attach files
  • kara convert commented
    May 08, 2020 14:49

    The fact that we are in 2020 and still cannot generate an EFT file from AP with PPD and are told by Viewpoint to manually change an EFT file is completely unacceptable. This should be a standard feature.

  • Valerie Burnett commented
    March 19, 2018 16:06

    One concern is that paying individuals through AP on an EFT requires changing CCD to PPD in the data file.  Vista KB requires that adjustment to the data file in order to process payments to individuals as opposed to corporations.  The file creation process would need to require an option for CCD or PPD if this were to be locked down for audit purposes.

  • Paula Bortolussi commented
    May 23, 2017 17:05

    The proposed solution is precisely what we were thinking - sounds good.

  • Troy Hagen commented
    May 12, 2017 13:27

    Gary – I don’t think this is going to work. This method would still allow a user to copy the data and paste it into a notepad txt file, manipulate it and upload it.

    Can we have a conference call to discuss?

    T

    Troy Hagen
    Director of Information Technology
    O 763-262-7017 | C 612-281-3621
    troy.hagen@mnlimited.com

  • Andre Ferreira commented
    May 11, 2017 23:00

    Hi Gary,

    Instead of changes being audited, I think any file modifications should be audited. Such as creating a file etc. Preferably with the audit log containing the information on the transaction.

    Though you would also need a way for naming conventions. Currently, all eft files are created with preftactivetext.aba for example. Though we always save them as  <yyMMdd>.aba so they are ordered by sequence. They are also ordered by date then year then month, so all months are together and all years are together.

    So maybe another field where you can put text then a date format so we could either have text first then date, or date then text etc.

  • Admin
    Gary Gilmore commented
    May 11, 2017 22:52

    How's this for a possible solution?

    Companies with concerns about access to AP and PR EFT files would be provided an option to specify a secure network location where all EFT files would be created and saved. 

    Permissions to this location would be controlled by the customer's site/security admin and restricted from general access (i.e. the user creating the EFT file would not have permission to read/write files to this location). 

    Because of its higher level access, the Viewpoint network services account would be used to create EFT files and save them to the designated location.  From there, they would be retrieved by another user with permissions to upload files to the customer's bank for processing.

    AP and PR would be allowed separate locations by company - control would be provided from respective company setup forms and any/all changes would be audited.

    If a location is specified for the module and company, then the EFT process would force a file save to that location and not allow user override.  File save would use the network service account because of its elevated permission.  Customer admin would be responsible for network file locations and permission management.
  • Guest commented
    May 11, 2017 20:53

    This is a significant security risk.  Any Vista-generated EFT file should not be able to be modified after it is created.

Dear Viewpoint Suggestion Box contributor;

We at Viewpoint sincerely thank you for your contribution to Suggestion Box on how we can improve Viewpoint products. While we can’t do everything at once, we rely upon your feedback to help guide the prioritization of our product improvements, and Suggestion Box is a critical tool for us to understand and prioritize our customers’ needs. Viewpoint reviews Suggestion Box regularly for all of our products and updates statuses, adds comments, and performs various house-keeping (including deleting) as needed to ensure that Suggestion Box is maintained as a productive environment for product enhancements requests.

1515 SE Water Avenue, Suite 300, Portland, OR 97214 |  800.333.3197  | Contact Us | Terms of Use | Privacy | Support Policies

© 2023 Trimble Inc. All Rights Reserved. Viewpoint®, Vista™, Spectrum®, ProContractor™, Jobpac Connect™, Viewpoint Team™, Viewpoint Analytics™, Viewpoint Field View™, Viewpoint Estimating™, Viewpoint For Projects™, Viewpoint HR Management™, Viewpoint Field Management™, Viewpoint Financial Controls™, Vista Field Service™, Spectrum Service Tech™, ViewpointOne™, ProjectSight® and Trimble Construction One™ are trademarks or registered trademarks of Trimble Inc. or its affiliates in the United States and other countries. Other names and brands may be claimed as the property of others.