Restricting the ability to view profiles and department info of users in other departments

記事番号:04060

Screenshot: The "Prohibit Cross-Department Access" setting on the "Cross-Department Permissions" screen is outlined

In Users & system administration, you can restrict access to the profile screen and department information of users in a different top-level department. This feature is called the Department access control.

Illustration: This shows that a user whose top-level department is A and a user whose top-level department is B cannot view each other's profile screens and department information.

Opening the "Users & system administration" screen

Restrictions on viewing user profiles

When department access control is enabled, users in different top-level departments will not be able to view each other's user profiles and department information.
Users in the same top-level department can view each other's user profiles and department information, regardless of the level of their department.
Illustration: Multiple users in top-level department A and multiple users in top-level department B cannot view each other's profile screens and department information.Note that cybozu.com administrators can view each user's user profile and department information in Users & system administration Administration.

Search restrictions

When department access control is enabled, users in one top-level department cannot search for departments and users in other top-level departments.
Also, users in other top-level departments cannot be mentioned in comments.
There are also other restrictions on accessing user and department information. For example, users from other top-level departments won't be displayed on-screen.
For details, refer to the following section.
Actions restricted by department access control

Actions restricted by department access control

The following tables show the actions users cannot perform on each screen when Department access control is enabled.
For example, the cybozu.com administration table indicates that, when Department access control is enabled, non-administrator users cannot view the profiles of users from other top-level departments.

Restricted actions are the same for both PCs and mobile devices.

cybozu.com administration
Screen / dialogActioncybozu.com Administratorkintone AdministratorNon-administrator users
ProfileViewAllowedNot allowedNot allowed
Other than profileView
Select
AllowedNot allowedNot allowed
kintone administration
Screen / dialogItemActioncybozu.com Administratorkintone AdministratorNon-administrator users
The "App management" screenSettings: Updated byViewAllowedAllowedNot allowed
The "App templates" screenCreated byViewAllowedAllowedNot allowed
Space managementSettings: Updated byViewAllowedAllowedNot allowed
Space templatesCreated byViewAllowedAllowedNot allowed
Thread action managementUpdated byViewAllowedAllowedNot allowed
Action settings dialogAvailable toView
Select
AllowedAllowedNot allowed
Permission managementUser, department, or groupView
Select
AllowedAllowedNot allowed
Permissions for app groupsUser, department, or groupView
Select
AllowedAllowedNot allowed
App settings
Screen / dialogItemActioncybozu.com Administratorkintone AdministratorNon-administrator users
Form
User selection fields (Preset users)
View
Select
AllowedAllowedNot allowed
User selection fields
(Default value)
View
Select
AllowedAllowedNot allowed
Department selection field
(Preset departments)
View
Select
AllowedAllowedNot allowed
Department selection field
(Default value)
View
Select
AllowedAllowedNot allowed
Lookup field
(Initial filter setting)
View
Select
AllowedAllowedNot allowed
Related records field
(Filter)
View
Select
AllowedAllowedNot allowed
ViewFilterView
Select
AllowedAllowedNot allowed
General notificationsRecipientsView
Select
AllowedAllowedNot allowed
Per record notificationsNotification trigger
Recipient
View
Select
AllowedAllowedNot allowed
Reminder notificationsNotification trigger
Recipient
View
Select
AllowedAllowedNot allowed
GraphFilterView
Select
AllowedAllowedNot allowed
Process managementAssignee listView
Select
AllowedAllowedNot allowed
Conditions to take this actionView
Select
AllowedAllowedNot allowed
API tokenScreenView
Select
AllowedAllowedNot allowed
WebhooksScreenView
Select
AllowedAllowedNot allowed
Slack integrationScreenViewNot allowedNot allowedNot allowed
ActionsUpdated byViewAllowedAllowedNot allowed
Create action
Edit action
Available toView
Select
AllowedAllowedNot allowed
Available whenView
Select
AllowedAllowedNot allowed
Permissions for appUser, department, or groupView
Select
AllowedAllowedNot allowed
Permissions for records
Target recordsView
Select
AllowedAllowedNot allowed
User, group and department to grant permissions toView
Select
AllowedAllowedNot allowed
Permissions for fieldsUser, group and department to grant permissions toView
Select
AllowedAllowedNot allowed
Apps
Screen / dialogItemActioncybozu.com Administratorkintone AdministratorNon-administrator users
View
  • Created by
  • Updated by
  • User selection fields
ViewNot allowedNot allowedNot allowed
User selection fieldsSelectNot allowedNot allowedNot allowed
Department selection fieldsView
Select
Not allowedNot allowedNot allowed
Filter condition on the Filter and Create graph screenView
Select
Not allowedNot allowedNot allowed
Assignee listViewNot allowedNot allowedNot allowed
Add recordsUser selection fieldsView
Select
Not allowedNot allowedNot allowed
Department selection fieldsView
Select
Not allowedNot allowedNot allowed
Lookup filter conditionsView
Select
Not allowedNot allowedNot allowed

The following fields of related records:

  • Created by
  • Updated by
  • Assignee list
  • User selection fields
ViewNot allowedNot allowedNot allowed
Department selection fields of related recordsViewNot allowedNot allowedNot allowed
Edit records
  • Created by
  • Updated by
ViewNot allowedNot allowedNot allowed
User selection fieldsView
Select
Not allowedNot allowedNot allowed
Department selection fieldsView
Select
Not allowedNot allowedNot allowed
Lookup filter conditionsView
Select
Not allowedNot allowedNot allowed

The following fields of related records:

  • Created by
  • Updated by
  • Assignee list
  • User selection fields
ViewNot allowedNot allowedNot allowed
Department selection fields of related recordsViewNot allowedNot allowedNot allowed
Record details
  • Created by
  • Updated by
  • User selection fields
ViewNot allowedNot allowedNot allowed
Department selection fieldsViewNot allowedNot allowedNot allowed

The following fields of related records:

  • Created by
  • Updated by
  • Assignee list
  • User selection fields
  • Department selection
ViewNot allowedNot allowedNot allowed
Select assigneeSelectAllowedAllowedAllowed
Change assigneeSelectAllowedAllowedNot allowed
Status historyViewNot allowedNot allowedNot allowed
HistoryViewNot allowedNot allowedNot allowed
MentionView
Select
Not allowedNot allowedNot allowed
Printable version
  • Created by
  • Updated by
  • User selection fields
  • Department selection fields
ViewNot allowedNot allowedNot allowed
Status historyViewNot allowedNot allowedNot allowed
Spaces
Screen / dialogItemActioncybozu.com Administratorkintone AdministratorNon-administrator users
Create space dialog
Space settings dialog
MembersView
Select
AllowedAllowedNot allowed
Space portalList of membersViewNot allowedNot allowedNot allowed
The "Updated by" user of the Announcement sectionViewNot allowedNot allowedNot allowed
Thread detailsThread followers listViewNot allowedNot allowedNot allowed
The "Updated by" user of the body textViewNot allowedNot allowedNot allowed
MentionView
Select
Not allowedNot allowedNot allowed
People who like thisViewNot allowedNot allowedNot allowed
Action settings dialogAvailable toViewNot allowedNot allowedNot allowed
SelectAllowedAllowedNot allowed
People
Screen / dialogItemActioncybozu.com Administratorkintone AdministratorNon-administrator users
List of peopleScreenViewNot allowedNot allowedNot allowed
Profile of users for whom you do not have view permissionScreenViewNot allowedNot allowedNot allowed
ProfileMentionView
Select
Not allowedNot allowedNot allowed
People who like thisViewNot allowedNot allowedNot allowed
Messages
Screen / dialogItemActioncybozu.com Administratorkintone AdministratorNon-administrator users
Messages posted by users for whom you do not have view permissionScreenViewNot allowedNot allowedNot allowed
Notifications
Screen / dialogItemActioncybozu.com Administratorkintone AdministratorNon-administrator users
NotificationsSent byViewNot allowedNot allowedNot allowed
Notification detailsSent byViewNot allowedNot allowedNot allowed
Notification filter settings dialog boxSent fromView
Select
Not allowedNot allowedNot allowed
LocationsView
Select
Not allowedNot allowedNot allowed
Search
Screen / dialogItemActioncybozu.com Administratorkintone AdministratorNon-administrator users
Search resultsCreated byViewNot allowedNot allowedNot allowed
"Created by" filterSelectNot allowedNot allowedNot allowed
PeopleViewNot allowedNot allowedNot allowed