We have PSA (v3) setup in an customer environment that needs to protect project information from users. So we created business units and gave users roles with max priveliges on bu level.
Unfortunately a lot of records that PSA creates eg approval and actuals are created and owned by user SYSTEM and thererfor in the top BU. The users belonging to a child BU will not be able to see the actuals for there project.
I'm suprised that MS has intorduced a 'all or nothing' principle. Is there a supported way to deal with tighter security, but still all functionality in place, like approving, invoicing, credit invoicing?