Concept of Fixed access

In PiSA cubes, the interface PSC_IFC_FIX_ACC is used. A DTO with this interface additionally gets the field PSC_FIX_ACC. To this field, accesses can be written that are then always added to the new access string (PSC_ACC). This makes it possible to grant a contact permanent access that cannot be withdrawn by access inheritance of the process concerned.

In the access form, there is an additional column in the sublists (Fixed) if the underlying DTO has this interface. In this column, a lock is displayed. With fixed access, the lock is closed, otherwise it is open. The state can be toggled by means of a hyperlink.

Note: To use this feature, a PiSA cubes upgrade may be necessary.

The PSA_ACT DTO (activities) has this interface as a default. This allows the access that a user grants to the recipient of an internal message or to the new responsible to be given permanently. In the standard, the access is also registered in the PSC_FIX_ACC field.

Note: Please always check if manually granted access to an activity (fixed) should be permanent, or be valid only in the current project phase (not fixed). If necessary, change the record access accordingly.

Attention

Attention: The fixed access of an activity has nothing to do with the "fixed" flag of an activity of the task, appointment or phone call type. The fixed access concerns record access and is stored in a string field, while the "fixed" flag is a logic field that enables or disables a specific rule for delegated activities regarding field access of certain adjustable fields. In the case of an email, the "fixed" flag, if set, has no effect.

The fixed access is stored in addition to the record access in a separate field outside the system fields area, and is added back to the new access string after any access inheritance.

Use case

Given that you want to grant users permanent read access to an activity and at the same time ensure that no one else can read the content that is considered confidential.

To avoid or override that project access is passed down to the assigned activities – in accordance with the process definition when certain project statuses are reached –, use the concept of fixed access for the activity.

  • In the access wizard of the desired activity, enter the accesses to be permanently granted or blocked in the corresponding positive or negative list as fixed access. You can activate and deactivate the lock by clicking on the lock symbol in the first column of the respective positive or neg­ative list.
  • You cannot state a condition such as "locked for all others". Instead, explicitly specify the employees you wish to exclude as members of one or more access groups, and fix the access for the corresponding entries. These accesses then remain fixed to the activity even when project access is inherited (e.g. when a new order status is reached).
  • The granted access and the lock are fixed reliably because of the priority rule, according to which the entries of the negative list always have priority when evaluating the access string.