Clarity

  • 1.  Restrict Task view on ONE project?

    Posted Mar 06, 2017 09:39 AM

    We have a project for "Absences" in a specific country.  We need to restrict the ability of users to view any actuals posted against that project's tasks, due to legal requirements.

     

    Is it possible to restrict the Team and Tasks view on ONE project, and one project only?



  • 2.  Re: Restrict Task view on ONE project?

    Posted Mar 06, 2017 10:04 AM

    There is no way to exclude access rights, only grant them - so if someone has access to something that you don't want them to see then you need to examine how they got that access and perhaps change your policy.

     

    But I think* that unless you have actively given the project-plan right(s) ("Project - View Tasks" and similar) to users then they should just only be able to see the project basic details (and not the team details, nor task breakdown) while still being able to book time to assigned tasks (i.e. your absence task).

     

    So if you are giving out rights globally to users then you would need to revise that policy, if you are giving out rights by OBS then you would need to move your project outside of the usual OBS areas.

     

    (* - I'm GUESSing a little bit here, but I think that this is the way it works)



  • 3.  Re: Restrict Task view on ONE project?

    Posted Mar 06, 2017 12:05 PM

    I was afraid of that.  The issue is that we can't remove the "Project - View Tasks - All" from *everyone* for all projects.  People do have a legitimate need to see task info on other projects (finance group, etc).  For this one single project, apparently they want NO ONE to be able to view actuals (not PM's, admins, literally nobody).  I'm not sure that's even technically possible, since any rights we grant by group would be for ALL projects, and obviously we can't make actuals invisible to everyone on all projects.

     

    But I told them I'd ask around, so I am! 



  • 4.  Re: Restrict Task view on ONE project?

    Posted Mar 06, 2017 12:13 PM

    "The issue is that we can't remove the "Project - View Tasks - All" from *everyone* for all projects" - yes you can!

     

    What I've done in the past is create a new OBS, lets call it "Security OBS" with a single node of "Open".

    Tag every single project in the system (apart from your special one) with a Security OBS level of "Open" - then grant the "Project View Tasks" access right at OBS level to the "All Users" group.

    ( in my solution we also put the secret projects into a "Restricted" level of the OBS and then just allowed special-groups access to that, but you would not need that I think )

     

    Note that this method can prevent system admins from accessing the special-projects too because no-one has a global project view/edit right (although system admins could in theory grant themselves the right so its not water-tight).