-
Type:
Improvement
-
Resolution: Unresolved
-
Priority:
Major
-
Environment:
Improvement Request: Update the permissions to not allow all users to view all contact records.
Issue: Today all users of the system can view all contacts regardless of permissions. Even if the volunteer group assignment is removed and the individual is only set as an Animal Admin they can still view all contacts in the system.
Reason: Not all users have the need to see all contacts. Organizations have the need to protect their data and prevent possible misuse. For example, Animal Administrators should not be able to see full PII of users. Many lower level employees/volunteers should not be able to access this volume of PII. Their job may be only to schedule events and add the user from a selection menu but not access their records such as address, phone.