Visibility of all personally identifiable information via Search bar typeahead
Can someone please confirm that it is possible for any user to view the profile of any other user and that there's no way to control this?
We are introducing new groups of users to the tool, and they have a very limited layout. They don't have access to the People tab, but if any of those users just starts to type a few letters in the Search bar, the suggested values will start to populate with names of other users. From there, anyone can then select the name of and view a person's profile including name, manager and contact information.
This is a security risk and possibly a violation of company policies to reveal personally identifiable information in this way. If this is indeed the way the system behaves, then shouldn't it be treated as a vulnerability and addressed as a bug (as opposed to a system enhancement)?
I would like to hear if there are any other administrators with similar concerns or if someone has figured out a workaround. We are using Workfront Classic, so I don't know if this has been addressed in the new Experience.
Thank you.