Invoicing functionality that FOLIO needs to stay competitive (UXPROD-3439)

[UXPROD-4039] Granular permissions for downloading and viewing invoice attachments Created: 07/Feb/23  Updated: 25/Jan/24

Status: Draft
Project: UX Product
Components: None
Affects versions: None
Fix versions: Umbrellaleaf (R2 2025)
Parent: Invoicing functionality that FOLIO needs to stay competitive

Type: New Feature Priority: P2
Reporter: Dennis Bridges Assignee: Dennis Bridges
Resolution: Unresolved Votes: 0
Labels: acquisitions, lc-priority4, loc
Remaining Estimate: Not Specified
Time Spent: Not Specified
Original estimate: Not Specified

Release: Umbrellaleaf (R2 2025)
Epic Link: Invoicing functionality that FOLIO needs to stay competitive
Front End Estimate: Medium < 5 days
Front End Estimator: Khalilah Gambrell
Front-End Confidence factor: 20%
Back End Estimate: Medium < 5 days
Back End Estimator: Khalilah Gambrell
Back-End Confidence factor: 20%
Development Team: Thunderjet
PO Rank: 119

 Description   

Current situation or problem: Any user with the ability to see invoices can view and download attached files. Some of these audit documents could be confidential

In scope

TBD

Out of scope

TBD

Use case(s)

  • General council staff (Legal department) may need to review documents for IRS audit that other staff would not. They would not edit but view attachements.
  • There are things we might make visible to most users. Like copywrite document or PDF copy of invoice
  • There are other things we might want to be very restricted. Like an appraisal document or audit documentation

Proposed solution

TBD - User must have explicit permissions to download and view attachments. Allow user to add private attachments that only users with a specific permissions can see.

Links to additional info

Questions



 Comments   
Comment by Dennis Bridges [ 08/Sep/23 ]

Agree that using links to secure files would likely be best practice. Duplicating that sensitive data could add unnecessary risk.

As such this feature has been assigned to Ramsons to provide more time to confirm details. Users currently have the ability to link documents to invoice records and organization records.

Generated at Fri Feb 09 00:36:47 UTC 2024 using Jira 1001.0.0-SNAPSHOT#100246-sha1:7a5c50119eb0633d306e14180817ddef5e80c75d.