Understanding classified information labels
Who is this article for?
Ideagen EHSQ Enterprise or Decani module developers or administrators who are interested in classifying information.
A Module Developer or an Area Administrative role is required.
In certain applications, it's essential to clearly indicate sensitive or classified information so it's handled appropriately and in accordance with your company's policies and procedures.
- Roles, reporting authorities, and Record Access Control (RAC)
- Field-level visibility rules
- Attachments and export options
- Integration access
Designate the Classified Information field
- Objects: Display the Classified Information field prominently so users with access can easily find it.
- Reference data lists: When a reference data list drives the Classified Information field, make the classification options easy for users to search and find.
- Grids: Place the Classified Information field within the first few columns so users can identify the classification when scanning objects.
Control object-level access
Record Access Control (RAC) controls object visibility based on roles and the reporting authorities (RA) assigned to a Person or Team.
For example, access to an object can be limited to the Manager (person role) on the compliance team (team role) who works in the corporate office (RA).
Before you can apply RAC rules and define access (Persons, Teams, All, or All Assignees), remove the Access All Objects property from the role.
Add field-level logic
In addition to reporting authorities and object-level access, you can set roles to control individual field behaviors.
Depending on the role, information can be visible and displayed in bold red text, set to Invisible, or set to Read-only. These settings let you hide or restrict individual fields while keeping the rest of the object visible.
Set attachment safeguards
Review export and archiving settings
Data export/import configuration lets you exclude fields from module-to-module exports. Use these settings to prevent confidential information from being included when it should not be exported.
PDF archiving (PDF/A-3) embeds attachments as binaries for archived objects. Review the included attachments to ensure confidential information is included or excluded as appropriate.
Control API integration access
The Hidden Data (RESTConnect) field property prevents a field's value from being returned through the RESTConnect API by default. This field property works with a corresponding role property. Only users with the appropriate role property can retrieve the hidden field's data through the API.
This setting affects RESTConnect API responses only. It does not affect field visibility in the standard UI.
Restricting or hiding fields can result in sensitive information being exposed to unauthorized users or prevent authorized users from accessing information they need. Thoroughly test access restrictions before enabling them.