Customer data objects and restriction conditions

Customer data objects and restriction conditions allow you to grant or restrict access to customer-level information.

Customer data objects are listed in the All Customer Objects table window in the Customer Objects (SP) application. The list shows all of the data objects for which customer-level data restrictions have been set up. The restrictions are defined in the Restriction Condition table window.

You are provided a set of default customer data objects and restriction conditions. You can add or remove objects and conditions or change the default conditions. You can refresh the list to its original state, with the full set of conditions for all customer-level objects, using the Create Default Conditions action.

You can also view all conditions created in the Customer Objects (SP) application in the Conditional Expression Manager application. The Conditional Expression Manager shows all conditions used in various applications, not just those created in and used by the Customer Objects (SP) application.

The objects and their restriction conditions apply to all security groups in the Security Groups (SP) application. The combination of the customer data objects and conditions, as well as the customer authorization settings for a security group, determine the customer-level information that users can access.

For example, if it is specified that a group has access to the Customer object if the customer is ABC Corporation, then members of this group can see the ABC Corporation customer record in the Customer (SP) application. For users in this group also to see work orders for ABC Corporation, the security group must also have access to the Work Order object for that customer.

For all of the default customer objects, the restriction conditions are set up already. If you add customer-level objects using the Database Configuration application, create a customer data object restriction for each main object that refers to a customer to ensure that access to the customer is fully restricted to the appropriate security groups. A main object is the main record within an application, such as Location object in the Locations (SP) application.

Restriction types

Restrictions can be one of the following types:

For example, in the Asset (SP) application, Asset is the main object. A qualified restriction on Asset restricts access, according to customer, to assets in the Assets (SP) application. In the Locations (SP) application, assets are shown on the Assets tab. The main object in this application is Location, not Asset, so the qualified restriction on the Asset object does not restrict access to the asset information shown in the Locations (SP) application. However, a hidden restriction for the Asset object would prevent the asset from being shown in the Locations (SP) application. So, to restrict access to all asset information in all applications, based on customer, both qualified and hidden restrictions are applied to the Asset object.

Each object can have up to ten assigned conditions—one for hidden restrictions combined with each of the five levels of customer authorization in the Security Groups (SP) application, and one for qualified restrictions combined with each of the five levels of customer authorization.

See also

Customer Objects (SP) application

Default customer objects and restriction conditions