Parental relationship does not need “assign” permission to propagate the assignment

By | June 20, 2018

This might be something to keep in mind.. If you have two entities with a parental relationship between them, your users may still be able to re-assign child record to others even if they don’t have “write/assign” permissions on the child entity.

In the example below, Sales Person role does not give “write” and/or “assign” permissions on the Test SLA entity:

image

So a SalesPerson can’t do anything with Test SLA directly:

image

But they can still go to the parent record which is currently assigned to me:

image

And re-assign that record to themselves:

image

And here we go – that child “Test SLA” record is, now, re-assigned to the Sales Person user as well:

image

Leave a Reply

Your email address will not be published.