HRSD Employee Relations COE Security
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
an hour ago
What we're trying to accomplish: We created a custom HR Service called Probationary Period in the Employee Relations Case COE. We'd like to give an HR group access to Probationary Period cases and no other cases in the COE.
Approach 1: COE Security Configuration
I gave the group the sn_hr_er.case_reader role and created a COE Security Configuration rule which limits access to the Probationary Period cases only (HR Service = Probationary Period). However, members of the group have access to all cases in the Employee Relations Case COE. The COE Security Configuration rules don't seem to work in this COE like they do in the other ones.
Question: Do COE Security Configuration rules not work in the Employee Relations COE?
Approach 2: Custom role and ACLs
I created a custom role and created a custom ACL that gives that role read access to Probationary Period cases in the Employee Relations Case COE. Users with the role are able to see Probationary Period cases and do not see cases with other HR Services so this functions as intended. However, users with the role are NOT able to see HR Task records where the parent is a Probationary Period case. Even after creating an ACL to allow access, they are still unable to see the HR Tasks. There does not appear to be a Display Business Rule nor a Data Filter for this.
Question: What is blocking access to the HR Tasks where the parent is a case in the Employee Relations Case COE?
The documentation states
"HR Service Delivery supports the Employee Relations Case COE.
And it supports the following HR services: Report Misconduct and Accommodation Request."
Question: Does it not support custom HR Services like the other COEs ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
46m ago
@Michael Culhan1 You can accomplish this using COE Configurations but when you explicitly give access to the one HR Service it does not stop other HR Services from being seen by the same group. You do not need a custom ACL to accomplish this. The key is that if they are an ER Role member you will have to restrict other HR Services in the ER COE to other groups. Knowing more of the use case can allow me to be more specific on how this looks but you have to account for the other HR Services (restricting) to make your use case work as I understand it.
Regards,
Mike