Best way to make requests of a cat item visible only to a specific assignment group and its members
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
3 weeks ago
I want to make RITMS and tasks belonging to a specific catalog item visible to only one assignment group and it's members. It should be hidden from everyone else. This is due to privacy restrictions. What is the best way to do this? Is there a way to do this without touching ACLs or creating a custom role?
- Labels:
-
Request Management
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
3 weeks ago
Hi @MariaPravin
Yes there is - I would suggest that you could look into data filtration rule which is the exact purpose. It should be available OOTB.
If my answer has helped with your question, please mark my answer as the accepted solution and give a thumbs up.
Best regards
Anders
Rising star 2024
MVP 2025
linkedIn: https://www.linkedin.com/in/andersskovbjerg/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
3 weeks ago
Hi @MariaPravin
Hiding records from people is what ACLs are for, so there isn't a clean way around them here. You can skip the custom role though.
The catch is that ACLs grant access rather than take it away. A normal read ACL won't remove what the existing ACLs on sc_req_item already allow, so people carry on seeing the records. That thread is a good example, they built one with a custom role and it made no difference: https://www.servicenow.com/community/developer-forum/hide-visibility-of-ritm-and-sctask-of-1-catalog...
Use a Deny Unless read ACL on sc_req_item instead. That decision type runs first and blocks anything failing its condition, and nothing else can hand the access back. Your condition would be that the item isn't this one, or the user is in that group, which gs.getUser().isMemberOf() covers. Then repeat it on sc_task.
https://www.servicenow.com/docs/r/platform-security/access-control/acl-denial-behavior.html
Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
3 weeks ago
Hello @MariaPravin ,
For true privacy, the best approach is to use ACLs. UI filters, Client Scripts can hide RITMs/tasks from the UI, but users may still access them directly.
You can avoid creating a custom role by creating a Read ACL that checks:
- RITM/Task belongs to the specific Catalog Item
- User is a member of the required Assignment Group
For example:
Specific Catalog Item + User is member of Group => Allow access
Otherwise => Deny access
As per my understanding , without ACLs, there is no reliable way to enforce this privacy requirement.
If this helps you then mark it as helpful and accept as solution.
Regards,
Aditya
