data security on debriefs (rcl_debrief_headers)
Summary:
Our customer Domino Printing is a global organizations with service channels spread across many countries (or groups of contiguous countries in Europe like Benelux). For each service channel they have defined a Business Unit.
Now, as we are expanding our footprints by rollouts, we notice that in the Manage Work Orders and Charges UI there is no data security. I went to Security Console and notice that rcl_debrief_headers is not a protected resource
Now, we have an SOP where some debriefs are monitored by the field service admin for the channels. Now, if there is no data security then the channel admin in one country can view and edit debriefs belonging to other country. This of course is not acceptible.
Tagged:
0