Security Vulnerability **URGENT***

We employ a third-party bookkeeping service and have provided them a customized restricted Role. We have discovered that they can’t upload (internally–they can through a client portal) documents in “customer hub” with these settings:

If we select “Hub Content - Manage All”, then they can upload, but then it removes ALL restrictions from them seeing content that they aren’t authorized to view.

Please advise.

Also, I might recommend you put a disclaimer next to both the “Manage All” selection and “View All” selection that this will allow the user to have unrestricted access to all hub content regardless of “Restricted by user”.

Good afternoon David,

After further troubleshooting with you directly on the support task created for this concern, I’m noting on this post it’s determined that the missing permission is “Customers/Vendors - Edit”. Adding this permission to that customized restricted User Role is expected to allow that user to still upload documents to the Customer Hub without requiring them to have the permission “Hub Content - Manage All”.

Additionally, mentioning here in case any other may find it helpful that users can hover directly over the permission name for a brief description of what the permission entails for helpful reference.

Please don’t hesitate to reach me on the support task should you have any further questions or need additionally assistance with this topic.

Have a great day!

1 Like