Modern: Users Without Edit Project Rights Able to Mark Projects For Deletion
search cancel

Modern: Users Without Edit Project Rights Able to Mark Projects For Deletion

book

Article ID: 245007

calendar_today

Updated On:

Products

Clarity PPM SaaS

Issue/Introduction

In order for a user to have access to mark investments for deletion, the user needs to have edit access to the project and project delete access right.

The Classic works fine, however it does not work correctly in the Modern.

In the Modern, it allows a user to mark a project for deletion who 
1. has global access to delete project but
2. does not have edit access to all projects 

Use Case:  Portfolio Managers can VIEW ALL Investments but only Edit on OBS level 
- There is security right allowing Project Deletion on OBS level; however, this only works in Classic but not in Modern UX.  It looks like only Global Deletion security right is supported in Modern UX as per
following documentation: Delete Investments
 
Furthermore, as part of the documentation above, the following is stated:
 
You need to have the <investment> - Delete - All global access right and “Edit” access rights for investments that you want to mark for deletion.
The following access rights have been introduced in this release to facilitate the deletion of investments from Clarity. 
• <Custom Investment> - Delete - All 
• Idea - Delete - All 
(…)
 
Key Points to Remember:
• Any user with 'Delete – All (Global)' and 'Edit' access for Custom Investments, Ideas, or Projects, will have the ability to use the Mark for Deletion option
 
The issue is that our resources have Edit only on OBS level, yet with the Project - Delete – All security right, they are able to mark ANY project for Deletion and the ‘Delete’ job deletes it, so the ‘…and Edit for Project condition’ is not really applied

 

Environment

Release : 15.9.3

 

Resolution

This is reported as DE65675 and after Engineering review, the documentation was misleading and is now corrected.

Section: Mark Investments for Deletion

You need a minimum of
1. <Investment> - Delete - All global access right and
2. "View" access rights to investments that you want to mark for deletion.