Everyone can see each other's details. Anyway to stop it.

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • crmtesting
    Member
    • Oct 2024
    • 39

    #1

    Everyone can see each other's details. Anyway to stop it.

    So, in our very small firm, we create tasks using EspoCRM and we can assign/collaborate the task to others.
    The problem is to be able to allow everyone to assign task to others, a role is created which give read access to all profiles.
    This is not what we intend. I was wondering if there is a way to be able to assign task to others, but not read all the profile details. Is this how it is supposed to work or I have made some wrong configuration?

    for example, A should be able to assign tasks to B, but A should not be able to open B's profile and see his mobile/email etc.
    Last edited by crmtesting; 01-30-2026, 03:32 PM.
  • emillod
    Active Community Member
    • Apr 2017
    • 1562

    #2
    Can you show screenshot of the role for tasks and users? You should set permissions to read & edit to OWN for tasks

    Comment

    • crmtesting
      Member
      • Oct 2024
      • 39

      #3
      Originally posted by emillod
      Can you show screenshot of the role for tasks and users? You should set permissions to read & edit to OWN for tasks
      emillod I am sorry, it seems I wasn't able to explain the problem clearly. there is no problem with tasks.

      for example, A should be able to assign tasks to B, but A should not be able to open B's user profile and see his mobile/email etc.

      Comment

      • yuri
        EspoCRM product developer
        • Mar 2014
        • 9620

        #4
        You can use Field Level Security to hide certain User fields from users. You can set such restriction in the baseline role.

        Assignment requires access to the User record.

        Comment

        • crmtesting
          Member
          • Oct 2024
          • 39

          #5
          yuri thank you very much for your comment but field level security does not help me, or probably I am not able to do it right.
          I tried field level security for local address field of a CRM user and it got removed for EVERYONE!
          The desired behavior is: one shall be able to read and edit their own local address and not read others' local address. Is it possible?

          problem: if a CRM user has their local address in their user profile. If I use field level security, either no one can see their own local address or everyone can see each other's local address. I want everyone to read and edit their own local address but not other employees'.


          Comment


          • yuri
            yuri commented
            Editing a comment
            I don't think it's currently possible. The field level access control has only yes/no granularity. Maybe in future it will be extended, but it would be not an easy task.
        • dreginald
          Senior Member
          • Sep 2018
          • 175

          #6
          Try assigning with a different related entity where the contact details are blank

          End-to-End EspoCRM Implementation & Customization by *astTECS Redefine efficiency, transforming static data into living insights. Talk to our Experts *astTECS Implementation Excellence - From Blueprint to Business Impact *astTECS’s CRM implementation team possesses a mix of technical expertise, business insight, change management skills, and stakeholder engagement abilities

          Comment

          Working...