Attachment security on HR Cases - outside of Evidence on Employee Relations

Beth Clingenpee
Giga Guru

Our HR Agents are asking for a way to attach documents to any HR cases and have an option to make them not visible to the Subject person. These are cases that are not necessarily Employee Relations cases where the Evidence tab is available, but there may still be times when it would not be appropriate for the Subject person to have access to an attachment added to another type of case.

 

We do not have "Field Encryption Enterprise", which appears to be required to create a new configuration for the attachment table. I've only explored the "Field Encryption Starter" a little, so I may have missed something there. I'm not sure that the attachments necessarily need to be encrypted - just secured.

 

Any assistance and suggestions welcome!

10 REPLIES 10

pavani_paluri
Tera Guru

Hi @Beth Clingenpee 

 

Create a restricted attachment mechanism (either a custom table or ACLs on sys_attachment).
Test with impersonation: impersonate a Subject user to confirm they cannot see or download the restricted files

 

Mark it helpful if this helps you to understand. Accept solution if this give you the answer you're looking for
Kind Regards,
Pavani P


 

Kohei Tominaga1
Tera Guru

Hi, @Beth Clingenpee 
The correct approach is to use Personal Notes in HR Agent Workspace for attachments that must not be visible to the Subject Person. Personal Notes allow HR agents to add comments and attachments that are restricted to the agent only, without requiring Field Encryption or custom attachment security.

Kind Regards,

Kohei

@Kohei Tominaga1  - this makes the most sense to me; however, I am not sure how to get the Personal Notes to show up on the contextual side panel. I'll admit that the UI builder is not my area of expertise, but I have explored that setup some this morning and see where the Page collection named Private Notes is included, but it is not showing on the case view. I also found under the settings on the HR Agent Workspace that Private notes should be visible. I'm sure I'm missing something!

Hi, @Beth Clingenpee 
Personal Notes is visible when the HR case is assigned like attached screenshot.

KoheiTominaga1_0-1767479027080.png

If my answer helps you, please hit "Helpful" and Accept as solution