Unconstrained security groups aren't context-sensitive. When users are members of
unconstrained security groups such as
Absence Administrator
or
Manager
(Unconstrained)
in addition to
Employee as Self
and enter time off for
themselves, they have both sets of permissions. They can view all of the time offs that
they're eligible for.
To resolve this situation, remove the unconstrained security
groups from your time off segment-based security groups. Use constrained versions of
the security groups instead so that users see the appropriate time offs for each
context.
Constrained groups are context-sensitive. When users are members of
constrained security groups such as
Absence Partner
or
Manager
with access
to specific time off security segments, they can only view the appropriate time offs
when entering time off for another worker using these tasks:
When members of the
Absence Partner
group enter time off for themselves,
they use the
Employee as Self
context and can only view the appropriate time offs
for Employee Self Service (ESS). However, if you've a time off segment for workers and
another for the
Absence Partner
role, when absence partners support their own
organization, they can request time off using time offs in both segments. To prevent
this, ensure that a different absence partner supports those absence partners'
organizations.