Customer-level data restrictions and customer authorization

You can restrict access to customer records by defining customer authorization levels and customer-level data restrictions in the Security Groups (SP) application. You can define security groups with different levels of access to different customer-level information.

Customer-level data restrictions limit access to customer information—any information that directly refers to a customer or is indirectly associated with a customer. For example, records in the People (SP), Customer (SP), Customer Agreements (SP), Service Request (SP) and Work Order Tracking (SP) applications all directly refer to a customer (there is a Customer field on the record). Records in the Assets (SP), Configuration Items (SP), Locations (SP), and Classifications (SP) applications can directly refer to multiple customers. In the People (SP) application, in addition to the person’s employer, a person record can list other customers to which the person has access. For example, if the person is an employee of the service provider and can access all of the customers of the provider, that user’s person record would list all of the customers.

Some customer-level data is not associated with a customer and is unrestricted information. For example, assets that belong to the service provider rather than to any of its customers do not have customer associations. Any users who belong to a security group that allows access to unrestricted data can see these assets.

Customer-level data restrictions work within the larger set of application restrictions and with other object, attribute, and collection restrictions to form the overall security profile of a security group and its users.

The customer-level objects that can be restricted according to customer, and their restriction conditions, are defined in the Customer Objects (SP) application. The level of customer authorization, specified on the Customers tab in the Security Groups (SP) application, determines the level of access to these objects.

See Also

Assigning levels of customer authorization to security groups

Levels of customer authorization