ERP Integration (EDGEBIC)

Who Should See Your ERP Export Files

User Solutions TeamUser Solutions Team
|
9 min read

A scheduling export set is more sensitive than it looks: together it can carry customer names, prices, quantities, due dates, part numbers and labor rates, and the files themselves are governed by your file system rather than by the application. In EDGEBIC by User Solutions the import function sits inside the permission-controlled Settings area with access granted through roles, but that control ends at the application boundary. The folder your nightly export lands in is your responsibility.

What is in the files

Take the five exports a typical integration uses and read them as one collection rather than five spreadsheets.

ExportCarriesSensitivity when combined
ProductsPart numbers, descriptions, unit prices, lead timesYour catalog and what you charge
Work centersMachines, instance counts, hourly ratesYour capacity and labor cost
RoutingsOperation sequences, setup and run timesHow you make things, and how long it takes
OrdersCustomers, references, quantities, due datesWho buys what, when, and how much
ActualsHours and pieces per operation per dayReal performance against plan

Individually, unremarkable. Together, in one browsable folder, that is a competitive briefing on your business, assembled by accident because convenience was the goal.

Routings deserve a particular mention. A full routing export is your manufacturing method, which is often the thing a shop would least like a competitor to read, and it is rarely thought of as confidential because it lives in an engineering system all day.

Where the application's control ends

Worth being exact about, because it determines what you have to do yourself.

Inside the application. Import lives in the permission-controlled Settings area. Access comes from roles rather than per-user settings, so you manage it by deciding which roles exist and who belongs to them. Every run writes one log file recording each row's outcome and any failure reason.

Outside the application. The export file is an ordinary xlsx or csv sitting wherever your export job wrote it. Nothing in EDGEBIC encrypts it, restricts who can open it, or removes it afterward. Those are file system and process questions.

That split is inherent to a file-based integration, which is how the whole integration works: something outside produces a file, an import mask loads it. There is no connector holding credentials and no sync service with its own access model, which removes a category of risk and hands you a folder to look after.

Who needs access

Keep two lists, and keep both short.

Who can produce the export. Usually one person or a scheduled job with database or ERP access. This is the technical half and it is bounded.

Who can run the import. The people who own master data and the planning cycle. Import changes data, so it belongs with them rather than with everyone who reads a schedule. Since permissions come from roles, the practical action is to review which roles include Settings access and prune the membership rather than looking for a per-user switch, because there is not one.

A useful test: if someone's job never requires them to change what the plant is planning against, they do not need import access, however senior they are.

Where the files should live

Four practical moves, none of them dramatic:

  1. Give the export its own folder, not a general-purpose share. This is the highest-value change on this page and usually takes five minutes.
  2. Grant that folder to the small group who produce and consume it. Most offices are browsing a share that was opened up years ago for a different reason.
  3. Use a stable path with a predictable file name. Good for reliability, and it also means you are not scattering copies with ad-hoc names in convenient places.
  4. Set a retention and delete on a schedule. Keep a few cycles for diagnosis, since when a schedule looks wrong the file that produced it is the fastest way to tell whether the data or the mapping was at fault. Beyond that the folder is accumulating sensitive data with no operational purpose.

Apply the same clear-out to import logs, which are also retained until you delete them.

Operational record versus audit trail

These get conflated, and it matters if your requirement is regulatory.

What exists is an operational record: one log file per run, showing exactly what each run changed, with reasons for failures. That is genuinely useful and it is what reading the import log after a nightly ERP run is about.

What does not exist is an in-app screen for browsing security or access history. So if you need to answer who opened a file or who held a permission on a given date, the controls have to come from the layers that offer them: your file system's own auditing on the export folder, and the discipline of a short role list. Decide which you actually need rather than assuming the application answers a question it does not claim to answer.

A short review worth doing once

Ask four questions, once, and write down the answers:

  • Which folder do the exports land in, and who can browse it today?
  • Which roles grant import access, and who is currently in them?
  • How long do export files and import logs stay there?
  • Who is told when someone with access changes job?

That last one is the gap in most shops. Access lists are created carefully and then never revisited, so the person who set up the integration three roles ago still has everything. Tie the review to whatever process already handles leavers rather than inventing a new one, and pair it with the ownership decisions in who owns the ERP import routine on your team.

The takeaway

Your ERP export set combines customer names, prices, quantities, due dates, routings and labor rates into one place, which makes the folder more sensitive than any single file in it. The application controls who can import, through roles rather than per-user settings, and records what each run did in a per-run log; it does not control the files on disk or offer a browsable access history. Give the export a dedicated folder with a short access list, set an explicit retention for files and logs, and review who holds import access when people change job. See the platform on the EDGEBIC overview, the upgrade path on the RMDB to EDGEBIC guide, and pair this with specifying the ERP export you need from IT and the data import governance workflow in EDGEBIC.

Expert Q&A: Deep Dive

Q: Our export lands in a shared network folder that most of the office can browse. Is that a real problem or are we being precious?

A: It is a real problem, and the reason is aggregation rather than any single field. Nobody worries about one part number. The concern is that a scheduling export set, in one place, tells a reader your customer list, what each of them pays, what they have ordered, when it is due, and what you pay per hour to make it. That is a competitive briefing document assembled by accident, and it is sitting somewhere convenient precisely because convenience was the design goal. The fix is proportionate rather than dramatic: give the export its own folder rather than a general share, grant access to the small group who produce and consume it, and keep the retention short. You do not need encryption or a new system for this. You need the folder to stop being browsable by people who have no reason to read it, which is a five-minute permissions change on the file share and the single highest-value thing on this page.

Q: Does EDGEBIC track who imported what, so we have an audit trail?

A: It records what each run did, not a browsable security history, and it is worth being precise about the difference so you do not plan around something that is not there. Every import writes one log file per run recording each row's outcome and the reason for any failure, which is a strong operational record: you can tell exactly what a given run changed and when. What there is not is an in-app screen for browsing security or access history. So if your requirement is regulatory rather than operational, the controls have to come from the layers that do offer them: your file system's own auditing on the export folder, the discipline of a short role list for who can import, and the run logs kept as your record of changes. Decide which of those you actually need rather than assuming the application will answer an audit question it does not claim to answer.

Frequently Asked Questions

Ready to Transform Your Production Scheduling?

User Solutions has been helping manufacturers optimize their production schedules for over 35 years. One-time license, 5-day implementation.

User Solutions Team

User Solutions Team

Manufacturing Software Experts

User Solutions has been developing production planning and scheduling software for manufacturers since 1991. Our team combines 35+ years of manufacturing software expertise with deep industry knowledge to help factories optimize their operations.

Let's Solve Your Challenges Together