Table record restriction
Overview
While PermissionsPermission is used to define which Table(s) and Field(s) users can see and/or edit, this capability is used restrict visibility to subset of records within a Table. For example, if a subset of users is only allowed to view Incidents that they raised or raised for them, the following need to be configured:
- A role (or can use an existing Role if it fits your broader security model)
- Permission(s) to allow Read access to the Incident table for the Role in step 1 above
- Table record restriction to restrict access to Incidents raised by or raised for currently logged on user, if the user has the Role in step 1 above
- Role assignment to the User(s) that need to get such restriction (can be done via Group membership too)
How it works
- Whenever a query is performed on a Table, and this includes viewing a record directly via a link, the platform checks if there is any Table record restriction defined for the Table
- If there is, the Query script defined in a Table record restriction will run. This script may return an extra Table Query
- If there is an extra Table Query returned for the User, it will be added to whatever query a User use for the Table
Example
- A user is querying for open Incidents
- There is a Table record restriction for Incident configured, and it is active
- The Table record restriction's Query script checks if the currently logged on user has a particular Role. If the User has it, the script is to return an extra Table Query of Incidents with Requestor or Requested for, being the currently logged on user
- If the User has that Role mentioned above in step 3, then the query in step 1 above will return Open Incidents, but only ones with Requestor or Requested for, as themselves
Configuration
For Table record restriction configuration, the below needs to be filled in:
Field name | Description | Example |
|---|---|---|
Name | Name of the Table record restriction, give it a meaningful name | Incident - Record visibility restrictions |
Description | What the Table record restriction does, be descriptive | The restrictions for incident records for non agent users. |
Active | If activated, the Table record restriction will always run for every query on the specified Table | Yes |
Table | Which Table the Table record restriction runs on | Incident |
Query | The restrictions to apply on the Table. You can add different kind of restrictions based the User's information such as Role(s) and Group memberships. The script has to set answer variable If answer is not set, then no extra Query is added (no extra restrictions added) | Example code below |
Example Query
//If the user is able to read the table, but does not have the agent role, they can only see Incidents that they are Requestor or Requested for
if (!user.hasRole("itsm_agent")) {
answer = OR(
EQUAL("Requestor", user.getID()),
EQUAL("RequestedFor", user.getID())
);
}