We are dipping a toe into the Control Group waters for the first time, in order to facilitate Plan usage across more departments.
Our Marketing department would like to use Plans to track engagement with community partners. This requires a new set of Plan values, separate from the pre-existing plan values used by our Development department.
My needs:
My plan was to:
The first problem I've encountered, perhaps obvious to those more familiar with control groups, is that when the Marketing user without access to the Dev General CG is looking at a Development Plan with Dev General CG'ed values, those values show up as their numerical ID number.
I tried associating the Marketing UG with the Dev General CG but unticking the Edit box - that brings back the visibility, but doesn't seem to restrict permissions at all.
Is what I'm trying impossible?
Many thanks for reading and any insight!
I'm not 100% on the specifics of controlling Plan access, but almost all Control Group schemes fall down on this:
Allow users who cannot USE Development plan values to still SEE those values on a plan
This is an issue we've had with Control Groups on CSIs. Basically, Control Groups let you see/hide specific data while Security Groups give you view/edit access to specific interfaces. So you can either edit all Control Groups you can see, or you cannot edit any.
Our best idea for resolving it was building either a report or a custom screen where we could selectively override security considerations, perhaps using a custom table to address the more complex privileges, but generally our huge project backlog has not allowed us to actually address this issue yet.
Thanks for weighing in, Gawain. Too bad there's not a simpler solution!