Your achievements

Level 1

0% to

Level 2

Tip /
Sign in

Sign in to Community

to gain points, level up, and earn exciting badges like the new
Bedrock Mission!

Learn more

View all

Sign in to view all badges

Analysis Workspace Share Recipient Permission Enhancement

Avatar

Avatar
Boost 1
Level 2
addams
Level 2

Like

1 like

Total Posts

8 posts

Correct reply

0 solutions
Top badges earned
Boost 1
Shape 1
Give Back 3
Ignite 3
Give Back
View profile

Avatar
Boost 1
Level 2
addams
Level 2

Like

1 like

Total Posts

8 posts

Correct reply

0 solutions
Top badges earned
Boost 1
Shape 1
Give Back 3
Ignite 3
Give Back
View profile
addams
Level 2

10-11-2021

Description -

In Analysis Workspace when a user without Admin permission and only basic permissions to one report suite clicks the Share | Send file now menu option under the Recipients field they are presented with all users under our org (even old users who have been deleted from our org) which is a security concern.  This user without Admin permissions should not see any other user names than their own.  It is fine if the user manually enters in other email addresses but this user should not see other unrelated user names in our Adobe org.

 

Why is this feature important to you -

Improved security for our org so that non-admin users do not see the names of our other client users who they have no relation to and should not see.  Currently we cannot open up access to the Analysis Workspace feature since our client users will be able to see the names of other client users who they are unrelated to which is not acceptable.  Each client user only has access their own report suite so they should not see the names of users that have access to other report suites.

 

How would you like the feature to work -

This user without Admin permissions should not see any other user names than their own.  The user only has access to one report suite so they should not see users related to other report suites or other admin users.  It is fine if the user manually enters in other email addresses but this user should not see other unrelated users in our Adobe org.

 

Current Behaviour -

In Analysis Workspace in the Share | Send file now menu option under the Recipients field, the user without Admin permission and only basic permissions is presented with the names of all users under our org (even old users who have been deleted from our org).