Symptom
In SAP SuccessFactors, users with permission to Manage My Group can see user information
Environment
SAP SuccessFactors HXM Suite
Reproducing the Issue
- If a user goes to "Settings" > "Groups" > & creates a group, for example using people pool fields "Country" = Germany and "date of birth" for less than today, the group membership is updated with all users from Germany with a date of birth less than today, so basically every user from Germany.
- Then check the membership list by going to "Take action" > "display options" and selecting date of birth and/or country.
- Now the user can see all German users data (first name, last name, date of birth, job code, location, country). They can do this with any of the fields in the people pool, even if they just setup the Dymanic group for "Country" Germany. They can then see all users names, job codes and locations for anyone in Germany.
Cause
When a user gets the permission to Manage My Group, he/she can filter users without target population restriction for the fields like First Name, Middle Name, Last Name, Job Code and Location, and the specific general group fields under Mange My Group People Pool.
Resolution
Working as designed.
Keywords
sf, success factors, PLT , KBA , LOD-SF-PLT-DYG , Dynamic Groups (My Groups - Not RBP) , Problem
Product
SAP SuccessFactors HCM Suite all versions