---
sourceDocument: Zurich Employee Service Management
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/employee-service-management

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Employee Service Management

ft:clusterId :

    - emplsm

bundleId :

    - emplsm

workflow :

    - Employee


---

# Configure an employee relations case restriction

# Configure an employee relations case restriction {#ariaid-title1}

* Release version: Zurich
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Define what groups can view or access employee relations cases using Case Restriction
Configuration.

## Before you begin

Role required: admin and sn_hr_er.admin  
Warning:  
When creating case restrictions, be sure that you have at least one configuration that enables you to read these cases.

## Case restriction configuration {#hr-er-create-case-restriction__section_y12_w23_kfc}

## Procedure

1. Navigate to AllEmployee RelationsAdministrationCase Restriction Configuration.
2. Click New.
3. On the form, fill in the fields.  
   {#hr-er-create-case-restriction__table_hzl_qtx_zkb__entry__2}

   | Field | Description |
   |-|-|
   | COE | Center of Excellence (COE) that you want to restrict access to. Note: For more information on COE, see [HR Centers of Excellence data model](https://www.servicenow.com/docs/wKe75FD5by9f4oI_tXpjag "Organize HR data, services, and processes by functional discipline with the HR Centers of Excellence (COEs) data model."). |
   | Able to restrict cases | Option to enable members of a group to restrict access to all HR cases for the COE. |
   | Able to view restricted cases | Option that enables a group to view restricted HR cases for the COE. |
   | Application | The application that the case restriction configuration applies to. This field is automatically set to Human Resources: Employee Relations. |
   | Active | Option to activate the case restriction configuration record. |
   [Table 1. Case Restriction Configuration form]

   {#hr-er-create-case-restriction__table_hzl_qtx_zkb}
4. Click Save or Submit.
5. Add the groups that you want the case restriction configuration to apply to.  
   Note:  
   You can also restrict by role. Agents with the sn_hr_er.confidential role can access restricted ER cases.  
6. Click Update.  
   Note:  
   Collaborators on an HR or ER case can override COE security. But, ER cases with restrictions override collaborators. For more information, see [Create COE security](https://www.servicenow.com/docs/d5g0BoMLpxD7ZmiImLyeVA#configure-hr-coe-security "Place security on a COE to prevent a group from accessing another group's cases.").

   COE security policies are a way to easily restrict access to different COEs via configuration. The underlying COE security policy implementations are [ServiceNow ACLs](https://www.servicenow.com/docs/access?context=access-control-rules&version=zurich&pubname=zurich-platform-security&ft:locale=en-US).

## What to do next

Case restriction configuration enables the HR confidential group members to restrict a case using the Restrict button available on the case. When a case is marked as Restricted only the members in the HR
confidential group can view the ER case.

*[\>]: and then


