UAT Overview for Work Package #4 - Masking PII in HCM

Purpose: This guide is intended to aid Local Security Administrators and HR/Payroll staff engaged in User Acceptance Testing (UAT) the configurations made in the Page and Field Configurator, by activating Delivered Masking, or by segregating access to NEW Security Roles.  These changes enable masking of Personally Identifiable Information (PII) in the Human Capital Management (HCM) pillar. 

Audience: Local Security Administrators and HR/Payroll Staff.

Expand or collapse content Background on Requirements & Solution

The Security Administration System Improvement (SASI) Project Information Guide, contains all background details on the requirements and solution design work that lead us to our User Acceptance Testing effort for this new custom ctcLink Security feature.

Overview of Masking of PII Data in HCM Functionality

To help testers better understand how the new Masking of PII Data security feature works a Quick Reference Guide (QRG) has also been provided in the ctcLink Reference Center, under the SASI Project Information guide and also below:

Link to: Quick Start Guide for Work Package #4 

Organizational Change Management (OCM) Aids

Testing Information

Expand or collapse content UAT Meeting Information

Monday, October 6, 2026 9:00 am and repeated 3:00 pm

MORNING SESSION:9:00 A.M. Meeting Information:

Meeting Link: https://sbctc.webex.com/sbctc/j.php?MTID=m28b9f38e90306f1d465bda97115554a3

Meeting number (access code): 2663 832 7747

Meeting password: rMqJpPpF665

Meeting Recording: Available after meeting

AFTERNOON SESSION: 3:00 P.M. Meeting Information:

Meeting Link: https://sbctc.webex.com/sbctc/j.php?MTID=m05da36539b887034dbfb8064668bbf04

Meeting number (access code): 2661 191 7158

Meeting password: PZuk6fFmC67

Meeting Recording: Available after meeting

Join either session by phone:
+1-415-655-0002 US Toll
+1-206-207-1700 United States Toll (Seattle)

Presentation Materials:

Expand or collapse content UAT Open Q&A Sessions

Join us for an Open Q&A session regarding the WP#4 UAT

Wednesday, October 8, 2026 1:00pm

Meeting Link: coming soon

Meeting number (access code):

Meeting password:

 

Wednesday, October 15, 2026 1:00pm

Meeting Link: coming soon

Meeting number (access code):

Meeting password:

Expand or collapse content Access to the UAT Environment

The PQA Environment, where UAT activities are taking place, was refreshed on September 3rd, 2026 from Production.

Employee job data and the state of security User Profiles is as of end of business the day before the snapshot, so any changes (onboarding new hires, offboarding separating employees or adjustments to an individual user's security profile made on or after 09/03/2026 will not be in the PQA environment unless replicated there for testing purposes.

Expand or collapse content Requesting Access

To request access to the User Acceptance Test environment (PQA), follow the link below and provide the name, last 4-digits of EMPLID, email, contact phone number and college. Be sure to sign up Local Security Administrators and Finance staff who have the job duty justification to warrant them viewing PII data.

LINK: Access Request (Google Sheet)

Expand or collapse content Environment Access Instructions

Testing will occur in the PQA environment. Testers will be logging on using their EMPLID. In order to access the impacted pages where the masking feature is applied, testers would need to have one or more of the security roles that enable navigation to these pages.

Impacted User Query:

Run Report in Finance of those with the impacted “Masked” security roles: QHC_SEC_MASKING_USERS_ROLES

  • Run “Wide Open” (by Business Unit) and save Excel output.
  • Report will display ONLY those with Primary Permission List matching the Business Unit.
  • Report will list the “Masked” security role the employee has.
  • Will also display IF they have a role that triggers “unmasking” and whether the user also has access to highly sensitive data via Query.

The following security roles are affected (PII field masking) by these changes:

HCM Security Roles Where Masking Will Appear:

  • ZC Benefits Enrollments
  • ZC HR Employee Maintenance
  • ZC Payroll Data Maintenance
  • ZC_BN_CORR_DEP_BENEF_DATA
  • ZC_PY_CORR_EE_PAY_DATA
  • ZD Benefits Employee Data Inq
  • ZD HCM SOGI
  • ZD HR Central Config VW
  • ZD HR Employee Maintenance VW
  • ZD HR Inquiry
  • ZD HR Limited Person Job Info (this role does not display the regional tab)
  • ZD Payroll Data Maintenance
  • ZD_BN_VIEW_DEP_BENEF_DATA
  • ZZ Ben Admin
  • ZZ HR Employee Maintenance
  • ZZ Payroll Data Maintenance
  • ZZ Payroll Processing
  • ZZ SS Payroll
  • ZZ SS Workforce Administrator
  • ZZ_BN_MAINT_DEP_BENEF_DATA

This environment rests behind an OKTA instance and therefore you will be prompted to establish a password during activation.

Login Access Link: https://oktapreview.ctclink.us/

NOTE: If access was already granted, it will be noted in the Google sheet linked above with the word "Granted" - check the google sheet to confirm.

Testers who have already activated themselves in the PQA environment for other testing activities (concurrent UAT activities do occur in this environment) will not be required to re-activate as this is a shared environment for all concurrent UAT activities.

Having Issues Logging In? Contact the Security Team. ([email protected])

Don't Forget: You have the ability to reset your own password in Okta. If encountering password issues, try this first. You might be able to self-help quicker!

Also, if you're struggling after regular service hours, feel free to download the Tester Login Reference Guide (below) to see if the answer you need is in here:

Expand or collapse content Test Scenario Tracker

The Test Tracker provided (attached below) allows colleges to plan their testing activities. You can add the Name or EMPLID of each person who will be testing each scenario. The tracker includes the security roles that will be impacted by this change, a place to track the status of each tested navigation and security role combination and also provides the security roles used to 'unmask' a field on that navigation. In most cases there are at least two different security roles that could unmask the data. Test with each of those unmasking roles to ensure both function properly. Record your results in this sheet for a well planned and executed test! You do not have to submit your worksheet upon completion of testing, it is provided simply to help you organize your testing effort.

UPDATED Test Tracker as of 09/08/2026

Expand or collapse content Test Details & Navigation

To Verify Masking During Testing:

  1. Masked View: Navigate to the relevant page using a security role with access to view the page with masking enabled. This can be done by assigning the role to yourself or asking a HR/Payroll staff member with Production access that has that role. Testers without PII access can perform this initial pass to confirm data is masked.
  2. Unmasked View: Apply a role that unblocks specific field types (e.g., SSN, bank account numbers, Passport/Visa Permit data) and confirm the data is visible. Only testers authorized to view PII should perform this step using one of the following roles:
    • ZZ HR PII Data
    • ZZ HC Unmask SSN
    • ZZ HC Unmask Bank Acct
    • ZZ HC Unmask DOB
    • ZZ HC Unmask Passport
    • ZZ HC Unmask Drivers License

Quick Reference Guides (QRG) were developed that detail how to search for and engage with the each page:

 

Issue Resolution During Testing

Expand or collapse content Reporting an Issue

Still want to submit an issue? Please report your issue via the Service Desk.

Request Type: ctcLink Support > Special Project Activities > SASI Work Group Testing

Subject (begins with): SASI Work Package #4: <add your words...>

Expand or collapse content Work Package #4 Issues and Resolutions

Each Issue Will Be Represented by a Title

  • Issue Details: Outline of issue reported by another college during testing.
  • Research: Security team research notes.
  • Resolution: Explanation of the resolution discovered and any retesting needed to validate the solution.

Test Status: 

Expand or collapse content UAT Completion & Sign-Off - All Colleges

Once colleges have fully completed their User Acceptance Testing and are ready to sign-off the ctcLink Point of Contact will be asked to "sign-off" on behalf of the college.

Link to UAT Sign-Off (MS Form): Sign-Off Survey Form

Sign-Off form is open until Tuesday, October 19, 2026 @7pm

All College Sign-Off Status:

Colleges Confirmed Complete with Sign-Off: ~ Testing Not Yet Commenced.

  • none

Colleges Awaiting Sign-Off:

  • Bates Technical College
  • Bellevue College
  • Bellingham Technical College
  • Big Bend Community College
  • Cascadia College
  • Centralia College
  • Clark College
  • Clover Park Technical College
  • Columbia Basin College
  • Edmonds College
  • Everett Community College
  • Grays Harbor College
  • Green River College
  • Highline College
  • Lake Washington Institute of Technology
  • Lower Columbia College
  • Olympic College
  • Peninsula College
  • Pierce College District
  • Renton Technical College
  • SBCTC
  • Seattle Colleges
  • Shoreline Community College
  • Skagit Valley College
  • South Puget Sound Community College
  • Spokane District
  • Tacoma Community College
  • Walla Walla Community College
  • Wenatchee Valley College
  • Whatcom Community College
  • Yakima Valley College

0 Comments

Add your comment

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.