Securing Information in a SEF

Information in social enterprise folders can be secured using sensitivity. All users (both agency and non-agency) are assigned a sensitivity level. By assigning a sensitivity level to information in a social enterprise folder, only those users whose sensitivity level is equal to or greater than the assigned sensitivity level can access the information. Sensitive information within social enterprise folders is asterisked out. For example, an attachment within the social enterprise folder can be assigned a sensitivity level of three; only users with a sensitivity level of three or higher can view the attachment otherwise all references to the attachment are asterisked out.

Configuration options are available to determine whether or not sensitive information is viewable when there are components which pertain to multiple clients. For example, incident sensitivity can be set to a level equal to or lower than user sensitivity or equal to or higher than the social enterprise folder client with the highest sensitivity. The following social enterprise folder components can be secured using sensitivity:

Table 1. Description of Sensitivity Security for SEF Components
SEF Function Sensitivity Description
Attachments When creating an attachment, a user can only set the sensitivity to equal or lower than their own sensitivity level. Only users with the a sensitivity level greater than or equal to the assigned sensitivity level may view the attachment.
Meetings When creating meetings, a user cannot invite clients or case participants to the meeting unless the user sensitivity is equal to or higher than the client or case participant sensitivity.
Case Case sensitivity is set prior to when the case is added to the social enterprise folder and is derived from the sensitivity of the primary client. This also applies to external cases retrieved using the CPI. Only users with the a sensitivity level greater than or equal to that of the case will be able to view the case information.
Clients Client sensitivity is set prior to when the client is added to the social enterprise folder and is based on the person's participant sensitivity level. This also applies to external persons retrieved using the CPI. Only users with the a sensitivity level greater than or equal to that of the client will be able to view information regarding the client.
Communications When creating a communication, a user can only set the sensitivity to equal or lower than the user's sensitivity and equal or higher than the sensitivity of the communication correspondent.
Discussions Users creating a discussion, a user cannot set the discussion sensitivity to be higher than their own. When discussions are posted, the system compares the discussion sensitivity to the sensitivity of multidisciplinary team members. Only those members whose sensitivity is equal to or higher than the discussion sensitivity will be added as watchers.
Incidents When creating an incident, a user can only set the sensitivity to equal or lower than the user's sensitivity and equal or higher than the sensitivity of the affected client with the highest sensitivity. Users can view incidents only if they pass the sensitivity check for all of the affected clients.
Meeting Minutes Users can access meeting minutes as long as they pass the sensitivity check for at least one case participant on the meeting minutes. When recording meeting minutes, users cannot set the recorded meeting minutes sensitivity to be higher than their own or lower than the client (invited to the meeting) with the lowest sensitivity.
Notes When creating a note, a user can only set the sensitivity to equal or lower than their own sensitivity level. Only users with the a sensitivity level greater than or equal to the assigned sensitivity level may view the note.
Related Social Enterprise Folders To create relationships between social enterprise folders, a user must have a sensitivity of the client or case with the lowest sensitivity on either related social enterprise folder.
Transaction History Transactions created as a result of sensitivity processing will not be viewable to users who do not have the necessary sensitivity level.