GROW

config

The 'Assignable By' field is only managed by the HR Admin

This issue is found automatically by CODA.
Time to fix: 45min

Why is this an issue?

OOTB (Out of the box) roles are included with the HR application. These roles can read, write, and edit data and have access to HR information, but they shouldn't delegate these rights to other people.

The "Assignable By" field is only allowed to be filled out by HR Admin. Changes to this parameter may put the security of HR data at risk.

Best practices

Remove all the core roles other than the HR Admin from the "Assignable By" box in order to maintain the instance's integrity and security and to secure critical HR data.

The steps are as follows:

  1. In the Filter Navigator, search for Roles

  2. Search the record where the sn_hr_core.admin is not the Assignable By field

  3. Change the Assignable By to sn_hr_core.admin and Save.