Restrict access to sensitive personnel information
Protect confidential personnel data by marking skill files and custom fields as sensitive. Sensitive items are hidden from anyone who does not have sensitive content access, and appear to them as Restricted content.
Before you start
Access to sensitive personnel data is governed by dedicated permissions. Set them per role in Company settings > Personnel > Permissions:
|
Permission |
Controls |
|---|---|
|
Read sensitive skill attachments |
Viewing and downloading sensitive skill files. |
|
Create sensitive skill attachments |
Uploading new sensitive skill files. |
|
Update sensitive skill attachments |
Changing sensitive skill files. |
|
Delete sensitive skill attachments |
Removing sensitive skill files. |
|
Read sensitive custom fields |
Viewing the values of sensitive custom fields. |
|
Update sensitive custom fields |
Editing the values of sensitive custom fields. |
Note: Users without the relevant permission see Restricted content in place of the value, and cannot open, export, or import it.
Mark a skill file as sensitive
Skill files are uploaded in the Skills section of a personnel record.
- Open the personnel record and go to the Skills section.
- When adding or editing a skill file, enable Sensitive.
- Save.
The file is now a Restricted file. As the tooltip explains: "When enabled this file will only be visible to roles with sensitive content access."
Mark a personnel custom field as sensitive
- Go to Company settings > Personnel > Custom fields.
- Add or edit a custom field. Use Add custom field to create a new one.
- Enable Sensitive on the field.
- Save.
Only roles with Read sensitive custom fields can see the value; everyone else sees Restricted content. Only roles with Update sensitive custom fields can change it.
Where the protection applies
Marking an item as sensitive protects it everywhere the data is shown or moved, including:
- Employee lists
- The resource calendar
- Lookups
- Exports
- Imports
Note: During an import, a sensitive custom field is skipped for users without permission: "This is a sensitive field. It will be ignored during import because you don't have permission to update sensitive custom fields."