Role based access to work items - Not working as intended

I am having a little issue here, since I thought I could manage access to work items trough SCSM using Queues.  

I have 2 departments, one is IT and one is facilities. There is a queue for each using support Groups to differentiate the access to Work items. User roles are used to give access to queues.

This however seem to have no effect. In admin settings in Cireson I can see a "ANALYST AD GROUP". The AD Group used has both the IT and the Facilities Analyst AD Groups as a member. My guess is that this in fact is the reason why my Facilities analyst can view IT Work items, even though I thought I had limited this in SCSM.

I knwo I can limit that one Group can view using views, but that does not mean the Work items cannot be accessed trough a search.

Can anyone confirm the above and do you see a way to get around this problem? We had the impression we could easily use the Portal for shared services. 

 

12 replies