Users who have Access to detailed document search can access Compensation and Variable Pay form even when they neither have Executive Review Access nor on Route Map.
Reproducing the Issue
- Login as User who has Detailed Document Search.
- Reporting->Switch to Classic View->Classic Reporting->Detailed Document Search.
- Detailed Search->Document Name->Select Template which user does not have access to(User Should have not access to Executive Review or should not be on Route Map).
- Generate Report->Forms are Listed.
- Click on Any Form and Print Preview Opens in a new Window.
Compensation and Variable Pay does not check for permission at module level if user has access to detailed document search. Hence will still have access to form data.
This is expected behavior and is by design where Compensation and Variable pay is designed to ignore permission assigned at module level.
Detailed Document Search is meant only for Super Admin. And for other users its adviced to create a report with restricted view and provide access only to that report.
Note: Support Engineers refer to internal note for Jira refernce where Engineering has confirmed this behavior.
detailed document search compensation variable pay , KBA , LOD-SF-CMP-ADM , Admin Tools, Settings, Permissions , Problem