20 January, 2024
We have updated the inherited permissions for risks, issues, lessons and tasks if they meet the criteria outlined below. This update streamlines the assignment of permissions.
Updates to the inherited permission logic within risks, issues, lessons, and tasks
- Users can create risks, issues, lessons, and tasks directly from a form using the +New button and view them in the Summary of Activities table.
- Risks, issues, lessons, and tasks can be access via their respective logs (e.g., Risks & Issues, Lessons, Tasks).
- Additionally, users can create child tasks associated with risks, issues and lessons which are tracked in their respective logs and the Summary of Activities tables.
- Previously, risk, issue and lesson owner and members could access both the forms where the items were created or via the respective log but task owners or members could only access the item from the respective log and did not have access to the parent item or form.
- Now task owners and members have full visibility and edit rights of any parent items (e.g., risks, issues or lessons) and the associated forms (Records of Processing Activity, Data Protection Impact Assessments, Incident Management, and Processing Operation Assessments).
- Task owners and members do not have permission to delete the associated risks, issues, lessons, or forms.
- Note: A task's attachment Reviewers will not have access to view associated risks, issues, or lessons.