Despite the existing security role configurations and the recent enhancement of ball-in-court workflows to restrict permissions, the platform still presents an authorship control issue with unlocked records.
The issue arises because users with “create” permissions also have the ability to modify or delete content created by others.
This behavior applies to links, comments, and the “Done” checkbox in action items. We have observed that any user can modify or delete these elements, regardless of whether they are the original author.
Our expectation is that, based on the assigned security roles, users should only be able to create, edit, or delete records they have authored. However, this is currently not being enforced.
Additionally, assignees should be limited to commenting, responding, and editing their own comments and links, without the ability to modify or delete content created by others. This represents a security control gap within the platform.
Dear Viewpoint Suggestion Box contributor;
We at Viewpoint sincerely thank you for your contribution to Suggestion Box on how we can improve Viewpoint products. While we can’t do everything at once, we rely upon your feedback to help guide the prioritization of our product improvements, and Suggestion Box is a critical tool for us to understand and prioritize our customers’ needs.
Viewpoint reviews Suggestion Box regularly for all of our products and updates statuses, adds comments, and performs various house-keeping (including deleting) as needed to ensure that Suggestion Box is maintained as a productive environment for product enhancements requests.
© 2023 Trimble Inc. All Rights Reserved. Viewpoint®, Vista™, Spectrum®, ProContractor™, Jobpac Connect™, Viewpoint Team™, Viewpoint Analytics™, Viewpoint Field View™, Viewpoint Estimating™, Viewpoint For Projects™, Viewpoint HR Management™, Viewpoint Field Management™, Viewpoint Financial Controls™, Vista Field Service™, Spectrum Service Tech™, ViewpointOne™, ProjectSight® and Trimble Construction One™ are trademarks or registered trademarks of Trimble Inc. or its affiliates in the United States and other countries. Other names and brands may be claimed as the property of others.