Skip to main content

Private work items

Roles and permissions

The following roles can make an issue private:

  • Administrators with manager permissions

  • Compliance managers with manager permissions

  • Users with manager permissions

The following roles can make a request private:

  • Administrators with manager or contributor permissions

  • Compliance managers with manager or contributor permissions

  • Users with manager or contributor permissions

If you are working with work items that contain sensitive information, you can make them private. Making a work item private prevents anyone who is not a direct member from accessing it. Work items that can be made private include: issues and requests.

Note

If you make a request private and are working with an external auditor, you’ll need to add the auditor to the private request so they can access it and any linked proof.

When an issue or a request is private:

  • Users can't inherit access to the private issue or request from a parent object. For example, being a member of a control linked to the issue or request doesn't give a user access to the issue or request.

  • Users with inherited access are removed from the membership list when the issue or request is marked private. Users who are direct members are unaffected. For example, if a user is a member of a control linked to an issue, that user has inherited access to the issue, which will be removed when the issue is made private.

  • If a private issue or private request is linked to another object, such as a control, only members of the private issue or private request can unlink it from the object.

  • Users who are members of objects linked to private issues or requests can't open them. Issues and requests display only the ID number with a message: This issue is set to private.

    private-issue-grid.png
  • Reassigning work for a deactivated user gives the new user access to the private issue or request assigned to the deactivated user. For example, if User A is a member of a private issue A and their work is reassigned to User B, then User B has access to issue A.

  • If you export a private issue where you are not a member, the export record includes only the issue ID, the object type for any linked objects, and the linked object IDs.

  • If you export a private request where you are not a member, the export record includes only the request ID, reference, status, linked controls, linked labels, and source.

To make an issue or a request private, open the facepile for the item and click the Lock icon in the bottom-left corner of the facepile.

lock-icon.png