Skip to main content

Hi, we were surprised to realize that the standard HR LTU Licence provides access to the view “Employment Information” without any restriction. This view provides the global list of all our employees along contact data. That’s obviously a breach of data protection rules and as it is linked to LTU licence we cannot block it at permission set level. So is there a parameter somewhere that we may have forgotten or activated that provides such extensive data access ?

In the below picture I’m logged with such LTU licence and i could fetch information from any company, not only the one I’m assigned with.

 

Have you made all employees protected persons? You should activate this (in employee file/person record) and if employees are still visible after this, it’s a permission issue that you’ll need to contact your administrator about.


The employees listed in my exemple are all protected persons

 

And i am the administrator.

The easy way is of course to amend the permission set, but IFS forbids to change permissions related to LTU as they are supposed to be standard. I’m just surprised no one else was annoyed by the way permissions were set on this LTU… it s not the only problem we faced.


It is possible to change permissions with LTU users - we have around 30 LTU users and had to restrict their access to HCM and other modules as they had access to everything. 

IFS has their permissions the wrong way round - they give everyone access to everything and then you have to restrict access, when in reality, you want to restrict access to everyone and grant permission based on user requirement. 


Hi,

I will be very thankful to know how you achieve it without extensive negotiations. I did already change something on this LTU in the past. It took months, we had to negotiate, they wanted to make us pay more as it is not considered as LTU anymore if you change it. We could not do the change ourselves, and their consultant made additional mistakes during the change … a nightmare.


Hi Ludovic, 

I spoke with our IT manager and he confirmed that he actually had to change the LTU users to a Full User and then create a permission set based off of our requirements. I can pass on his details if you want to discuss this further on how he achieved it? 


Reply