COE Security Policy to restrict access to cases based on Assignment Group

Yessi
Tera Contributor

Hey SN Community! 

Is it possible to restrict case access for HR Agents based on their assignment group using a COE Security Policy?

For example: Person A is apart of HR Tier 1. There are currently 4 HR Benefits Cases. One is assigned to HR Tier 1, so Person A should only be able to view that 1 case out of the 4 available.

I've attempted to create a policy for our Benefits table, applicable to all services, and applies when condition - Assignment group is (dynamic) | One of my groups. I've attempted listing all our assignment groups and then again limiting it to a few. Either way all cases are viewable to everyone. Once I remove the Applies when condition, the COE Security Policy works and restricts access to those outside of the listed groups. Is it possible I'm using this Applies when condition incorrectly? Is it limited to certain use? Is anyone able to share examples of COE Security policies they've created?

 

Yessi_0-1719969504589.png

Test Profile is not part of any of the listed groups but is still able to see Benefits cases.

Yessi_1-1719970201718.png

Appreciate any feedback and tips!

1 ACCEPTED SOLUTION

@Yessi Here is my configuration. I will have to test your use case based on your configuration (images you sent) but here you have to restrict all cases in order to use your second COE policy that states the allow. In my example I am restricting all COEs to only those that are in the assignment groups of the case are able to see.

 

Blocking all cases

michaelj_sherid_0-1721419525138.png

 Allowing any case assigned to one of my groups

michaelj_sherid_1-1721419576061.png

 

Regards,

Mike

 

 

View solution in original post

19 REPLIES 19

Sandeep Rajput
Tera Patron
Tera Patron

@Yessi All assignment groups in HR usually share a common parent which is HR Assignment group. This might be the reason why the assignment group condition is evaluating to true even if the user is not part of the assignment group.

 

Please test the condition with those groups which do not share a common parent and see if the condition works correctly.

Hey @Sandeep Rajput 

I tested this in my PDI environment to avoid removing the HR parents within our own test environments. I'm still able to view Benefits cases using that condition. Any other items you think could impact this condition from working? Have you utilized COE Security policies before? 

This is quite strange, I will verify this on my PDI and let you know the outcome.

Appreciate it Sandeep!