Employee Relations Application Setup - ER Admin role
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-19-2023 05:30 PM
Hi,
I am learning how to setup and how to use the Employee Relations application in my PDI with referencing Docs article.
In my understanding, ER cases include very sensitive data and they are strictly restricted to be accessed.
I have confirmed that ER agent can access ER cases but HR agent without ER case reader role cannot access them. I think this behavior is good but it is not good that HR Admin users can access ER case which I confirmed in my PDI.
Do I need to remove ER Admin role from HR Admin role like when I remove HR admin role from Admin roke? Is there any instruction to do so?
Best Regards,
Kohei
- Labels:
-
Case and Knowledge Management
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-19-2023 08:50 PM
When I go through HR Implementation e-book which is provided by Servicenow.
In that page no. 43 mentioned only few member of hr agent can access ER cases.
When we talk about HR admin, it will depended on organization to organization what are scopes define for HR admin.
If I could help you with your Query then, please hit helpful and mark as Correct.
Thank you
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-19-2023 10:53 PM
Hi @Kohei Tominaga1 ,
You are correct "HR Admin users can access ER cases" as HR admin contains of ER Admin role.
It's not a good idea to remove ER Admin role from HR Admin role. Also, note that in actual/company instances, a system admin with "Admin" access doesn't get HR admin role by default, in PDI it's a different story.
It's a best practice to not to provide with HR admin role to anyone but should be limited to only few users or 1-2 users specifically.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-19-2023 11:43 PM
Hi,
I saw this slide in this docment and thought that HR Admin cannot access to ER case. Is my understanding wrong?
>a system admin with "Admin" access doesn't get HR admin role by default
I think it is not correct because Docs is saying that "After system configuration, ensure that only the HR Administrator [sn_hr_core.admin] role has access to sensitive information. Remove the HR Administrator role from System Administrator [admin] role to prevent the System Administrator from viewing sensitive HR information."
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-21-2023 06:45 AM
Hi Kohei,
I believe the ServiceNow slide is also referring to restricted ER cases.
ER restricted cases are only readable by individuals with the "sn_hr_er.confidential" role and are part of the "Case restriction configuration" for ER.