Attachment security on HR Cases - outside of Evidence on Employee Relations

Beth Clingenpee
Giga Guru

Our HR Agents are asking for a way to attach documents to any HR cases and have an option to make them not visible to the Subject person. These are cases that are not necessarily Employee Relations cases where the Evidence tab is available, but there may still be times when it would not be appropriate for the Subject person to have access to an attachment added to another type of case.

 

We do not have "Field Encryption Enterprise", which appears to be required to create a new configuration for the attachment table. I've only explored the "Field Encryption Starter" a little, so I may have missed something there. I'm not sure that the attachments necessarily need to be encrypted - just secured.

 

Any assistance and suggestions welcome!

13 REPLIES 13

Good morning, @Kohei Tominaga1  - that was a good suggestion, but it appears that the subject person / opened for person is able to see tasks on the Employee Center under their My Requests widget, including any attachments even before the HR task is closed.

You’re absolutely right, and thank you for pointing this out. I had forgotten that HR‑related tasks can also appear in the Employee Center.
I also wish I had the same capability you described, so if you come across a good idea or approach, please share it in this thread — I’d really appreciate it.
For context, here’s my current situation:
In the certificate issuance process, I want to complete the review flow entirely within ServiceNow. The HR team creates the document, and then someone needs to review it. At the moment, we store the files in an external storage service, but ideally, I’d like to consolidate everything into ServiceNow if possible.
If anyone has solved a similar challenge or has suggestions on the best approach, I’d love to hear your thoughts.

Sandeep Rajput
Tera Patron

@Beth Clingenpee You can address this requirement by introducing a custom field 'Hide attachments from Subject person'on the sn_hr_core_case, this will be a checkbox field, agents can set the value of this field and choose to hide the attachments on specific cases. You will also need to update existing Read ACLs on the sys_attachemnt table and check current.u_hide_attachments_from_subject_person field value in the Read ACLs sys_attachemnt table.

 

Hope this helps.

Ajay_Chavan
Kilo Sage

hey @Beth Clingenpee 

 

If you have access to the OOB Employee Document Management plugin, it might be a good idea to check it out


https://www.servicenow.com/docs/bundle/zurich-employee-service-management/page/product/human-resourc...

 

Glad I could help! If this solved your issue, please mark it as ✅ Helpful and ✅ Accept as Solution so others can benefit too.*****Chavan A.P. | Technical Architect | Certified Professional*****