Quantcast
Channel: SCN : All Content - All Communities
Viewing all articles
Browse latest Browse all 8800

Non-MSS user can approve Missed Punch Log form

$
0
0

Hello Experts,

 

I have a problem where ESS endusers are able to approve a Missed Punch Log (MPL) for a different employee forwarded to them by a MSS enduser.  Only MSS users should be able to approve.  I cannot figure out which auth object is giving the ESS enduser the authorization to approve a MPL. 

 

My P_ASRCONT authorization values in the ZS:HR_ESS_ENDUSER_WORK_TIME role are:

 

OBJECTFIELDLOW
P_ASRCONTASROBJSCOP1
P_ASRCONTASRCONTYPEP
P_ASRCONTASRCONTGRP*
P_ASRCONTASRACTVTS
P_ASRCONTASRCONTYPEF

 

I also have these authorization values in the role:

 

OBJECTFIELDLOW
S_SRMGS_VVSPS_IDASR*
S_SRMGS_VVSRM_MODEL*
S_SRMGS_VVDOCUMENTID*
S_SRMGS_VVACTVT1
S_SRMGS_VVACTVT6
S_SRMGS_PRACTVT3
S_SRMGS_PRDOCUMENTID*
S_SRMGS_PRPROPGROUP*
S_SRMGS_PRPROPNAME*
S_SRMGS_PRSPS_IDASR*
S_SRMGS_PRACTVT6
S_SRMGS_PRACTVT2
S_SRMGS_PRACTVT1
S_SRMGS_PRSRM_MODEL*
S_SRMGS_DCDOCUMENTID*
S_SRMGS_DCSPS_IDASR*
S_SRMGS_DCACTVT1
S_SRMGS_DCACTVT30
S_SRMGS_DCSRM_MODEL*
S_SRMGS_CTSRM_MODEL*
S_SRMGS_CTACTVT1
S_SRMGS_CTDOCUMENTID*
S_SRMGS_CTACTVT3
S_SRMGS_CTSPS_IDASR*

 

I welcome any advice/recommendations for any authorization changes that should be implemented to prevent a non-MSS user from approving a MPL.

 

 

Thanks for all your help,


Viewing all articles
Browse latest Browse all 8800

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>