Restricting Creation of the Contract based on Access Groups
Summary:
Access Groups manage data visibility by attribute, but functional security still allows users to select unauthorized Contract Types during the creation process.
Content (please ensure you mask any confidential information):
We are currently implementing "Control Access to Contracts Using Access Groups" (as per the 26A features).
While Access Groups work well for controlling visibility and access to existing contracts based on attributes (e.g., Contract Type, DFF), we have noticed a discrepancy during the Contract Creation process.
The Challenge: Even if a user's Access Group is restricted to particular Contract Type, the user can still select any Contract Type from the dropdown when creating a new contract. This is because the "Create" action is governed by Functional Security (Privileges), which does not seem to be filtered by the Access Group's Object Rule logic.