I have a payroll group that will have their own attachments and notes. It's payroll sensitive so not all analysts should see their notes and attachments. I have a new collection object for both. Most incidents for this group do not contain sensitive data and they send incidents to other departments frequently. For sensitive info they can add the Payroll Attachment or a Payroll Note. Through a role and privileges I can restrict. I added a role for just the few extra permissions needed and removed those same permissions from the Analyst role.
So what's the problem? I was expecting a standard analyst to be able to open an incident with a payroll attachment or note but not be able to see it. Instead they get an error and can't open the incident at all. Is there something else I can do? I don't mind anyone viewing the non protected data.
I copied my Incident window and removed the Payroll Attachments and Notes from my main window and they exist on the copy. I then created views to point only payroll people to the new copy. They work fine. However, the standard analysts still could not open a Payroll incident if it has an attachment or note.