Reviewer Privilage Issue
When reviewer X submits a SR which has Y as a reviewer, X can open the submitted request and approve/reject the activity even though he is not the approver of that activity.
Have you encounter this issue before?
Best Answer
-
Geoff_Ross Cireson Consultant O.G.Hi,
This might help.
https://community.cireson.com/discussion/1400/only-allow-reviewers-to-approve-review-activities/
Geoff5
Answers
If you put a user in the AD group that you are then assigning in the portal admin settings as being able to approve, then you are overriding the SCSM built in permissions for this.
Really you should only use those groups for users that you want to have manager approval level permissions. A end user that is a reviewer already has the permissions to approve their own review activities. You should remove the group in this case and user the default SCSM permissions if you want to do what you are describing above.
In cases like this, you definitely have to rely on process to keep things on the up and up. You could also generate a report of CR's that were approved by the same person who requested it (work items related to review activity/ies that where the user object that voted is the same user as the work item creator), as a detective control. Seth already covered prevention.
This might help.
https://community.cireson.com/discussion/1400/only-allow-reviewers-to-approve-review-activities/
Geoff