Good afternoon,
i have a question related to security roles.
I have an entity named "X", that have Notes and Activities.
I have set the security role so that users can delete only their Note and Activities.
The situation is the following:
- If i'm the user A and i'm owner of "X" entity, I'm able to delete my own Notes and Activities and also Notes and Activities owned by user B, C, D, E....
- If i'm the user A and "X" entity is not owned by me, i can't delete Notes and Activities owned by other users, but i can delete only mine.
The question is: is there a way to avoid that user A, owner by "X" entity, can delete associated Notes and Activities owned by user B, C, D, E?
I'm sorry for my bad english :)
Thank you in advance.
Axel
*This post is locked for comments
I have the same question and verified the team has no security role assigned. should we still remove the user from the team?
Hi nikoleta,
Are the users in the same team? If so, you will need to remove them from the same team.
It looks like even though the user has Basic (User) level delete privilege, they still can delete activities that are owned by other users. Is there a solution to this?
Hi Axel1984,
The best way to solve this problem is by giving User A a Security Role with User level Delete Privileges on the Note and Activity privileges. You also need to make sure that User A does not have Business Unit, Parent: Child Business Units or Organization level Delete Privileges on the Note and Activity entities as Security Role permissions are cumulative. If User A has a Security Role with User level Delete Privileges on the Note and Activity privileges, but no security roles with greater Delete privileges for these entities, then the problem will be solved.
Stay up to date on forum activity by subscribing. You can also customize your in-app and email Notification settings across all subscriptions.
André Arnaud de Cal... 291,240 Super User 2024 Season 2
Martin Dráb 230,149 Most Valuable Professional
nmaenpaa 101,156