We have process admin users in our system with Manager access who are currently

We have process admin users in our system with Manager access who are currently completing Quick Tasks not assigned to them (specifically assignment to other groups) - per the security documentation (forum.appian.com/.../Configuring_Process_Security), I had thought this was covered under "View and complete tasks assigned to other users in the system" (not available for Managers). Since we use Manager access frequently to allow task reassignments for process administrators, I figured I would check with the Appian world to see if anyone else has found anything special & not documented regarding Manager access. Also, is this expected behavior for Quick Tasks?...

OriginalPostID-130231

OriginalPostID-130231

  Discussion posts and replies are publicly visible

  • As you observed, the core issue here is that the managers are able to complete tasks that were not assigned to them, which is different from what's described in the documentation. Given that the chart provided in the documentation is incorrect in this regard, this has been reported to Engineering (Ref. AN-40122) to update the documentation, since this is the expected behaviour.

    You could have a look at the chart to see if there are other roles that may be suitable for your use case. Keep in mind that the chart is also missing another privilege that exists for the Manager role - Reassign tasks when reassignment is disabled.
  • Thanks Abhimanyu.

    For a use case, are there any developers here with scenarios such as the need for administrative users to have the ability to reassign tasks for groups/departments, but not access some high level type quick tasks - if quick task permissions are assigned dynamically during the process? Since we have a 26,000 user base, we have to allow admin groups the ability to view processes and re-assign tasks, but keep them out of super-admin quick tasks at the same time. If these super-admin quick tasks are assigned dynamically at run time, we will not be able to segregate them with targeted channels on the dashboard. Would there be any suggested methods for this other than manually checking permissions with process design - say on quick task output or on the forms (doesUserBelongToGroup(), etc)?