Interested in a ServiceNow event built for developers? Registration for now[dev]26 is officially open!

CSM Case Visibility Issue: Department A users can view Department B cases in the CSM Portal

CarolMa6
Tera Expert

Hi, 

 

I need assistance with a CSM portal visibility issue. We have two separate CSM portals used by two different departments, and each department should only be able to view its own cases.

Recently, users in Department A have started seeing cases that belong to Department B, while Department B cannot see Department A's cases. This was not the behavior previously.

 

I suspected the issue might be related to the sn_customerservice_manager role, which was assigned to Department A users, but even after removing the role, Department A users can still see Department B's cases.

I need to identify where case visibility is being controlled and what may be causing this change in behavior.

 

Help please!

 

Regards, 

CarolMa

2 REPLIES 2

Kieran Anson
Kilo Patron

If best practice has been followed, this should be handled by CSM Query Rules. 

 

Portals don't control access, they just act as a way to brand the portal differently. Access will be controlled by role, relationships, and related data

musislam
Kilo Sage

Hi Carol,

Agreed with Kieran - the portal only brands, so I'd look in two places, in this order.

First, check the property sn_cs_queryrules.use_query_rules. If it's true your filters come from sn_query_rule records; if false they come from the CSQueryBRUtilOOBConstants script include. New instances default to true, upgraded ones to false - read the wrong source and you'll spend a day on rules that aren't firing.

Second, the asymmetry is the clue. A seeing B but not the reverse usually means data, not a rule. Check whether Department B's Account now has a Parent pointing at A, and whether any Department A contact holds sn_customerservice.customer_admin - that's the role that sees child-account cases. sn_customerservice_manager is an internal agent role, which is why removing it changed nothing on the portal.

Impersonate with Debug Security Rules on and you'll see exactly which query rule fires and the encoded query it builds.

If that points you at it, mind marking it as the recommended solution? Helps me support these better for the community.

Macki | Deloitte AU | Engineer Lead