Can anyone advise if it is possible to make Profiles read only through the Profiles screen (still updateable through workflows).


When creating custom resources, I'm able to define "Actions on data" and leave "authorise creating" unchecked.

Then on "detail screen" definition, I can also make all the fields "value" (rather than "input").


Given Profiles is a factory schema/resource.... is it possible to make it read only for all roles/security groups by hiding the create button - and setting the default fields in the detail screen to value rather than input?


No, this can't be done.

You could assign users to a child organizational unit, then they also only would have read permissions and can't do any modifications.

