We have two PR Groups in PR Group Master (Group 1 is restricted access, Group 2 can see all employees ;
We specify VA User Name under the Group Security tab in PR Group Master for each group.
we have secured bEmployee and bHRRef in VA Data Security Setup
The HR Resource Master functions properly, given the security parameters (ie....access is appropriately restricted)
And the report, HR Salary History, correctly restricts according to PR Group security.
However, when someone with restricted access launches HR Resource Salary History, they can see all employees.
My theory is adding the field PR EMP to HR Resource Salary would allow the controls in place to work as they should.
Company | Talley Construction Company Inc |
Job Title / Role | CFO |
I need it... | 6 months |
Dear Viewpoint Suggestion Box contributor;
We at Viewpoint sincerely thank you for your contribution to Suggestion Box on how we can improve Viewpoint products. While we can’t do everything at once, we rely upon your feedback to help guide the prioritization of our product improvements, and Suggestion Box is a critical tool for us to understand and prioritize our customers’ needs.
Viewpoint reviews Suggestion Box regularly for all of our products and updates statuses, adds comments, and performs various house-keeping (including deleting) as needed to ensure that Suggestion Box is maintained as a productive environment for product enhancements requests.
© 2023 Trimble Inc. All Rights Reserved. Viewpoint®, Vista™, Spectrum®, ProContractor™, Jobpac Connect™, Viewpoint Team™, Viewpoint Analytics™, Viewpoint Field View™, Viewpoint Estimating™, Viewpoint For Projects™, Viewpoint HR Management™, Viewpoint Field Management™, Viewpoint Financial Controls™, Vista Field Service™, Spectrum Service Tech™, ViewpointOne™, ProjectSight® and Trimble Construction One™ are trademarks or registered trademarks of Trimble Inc. or its affiliates in the United States and other countries. Other names and brands may be claimed as the property of others.
This is a massive security flaw. How has this not been addressed in over 5 years? We have the same issue in the latest version of the software, and after handfuls of support calls, they don't have an explanation why this table is not linked in bEmployee security so that it can be restricted by PR group security properly. To be able to access restricted, confidential employee salary history as a regular user in such a simple method of a backdoor is a gaping issue that should have been fixed as soon as this was submitted.
This request should be combined with VACCTG-I-918
Agreed. HR Resource Master functions properly with Data Security, but HR Resource Salary History, HR Resource Employment History, HR Resource Contact are not appropriately secured for users with restricted PR Group access.