Workflow Access Loophole - Reveal Contents

  • 1
  • Problem
  • Updated 3 months ago
Any person who has access to a parent folder that contains a Workflow is able to right click on any Workflow and click Reveal Contents to see every folder and file contained in that workflow, provided they have rights to the parent folder. This prevents any form of confidentiality when it comes to Workflow assignees uploading files that should be kept confidential from any other assignees on that Workflow. We originally understood the Workflow functionality to be confidential and allow only the assignee to view tasks assigned to them, but it appears that they do not have any privacy whatsoever. 

Why would the Reveal Contents button reveal Tasks that are not assigned to a particular assignee? The tech I spoke with made it seem like permission to the Workflow is only for approval purposes, but when we originally deployed the ShareFile solution, we were under the impression that assignees' uploads would not be accessible by other assignees. 
Photo of Jake Henry

Jake Henry

  • 2 Posts
  • 0 Reply Likes

Posted 3 months ago

  • 1
Photo of Adi Chand

Adi Chand, Employee

  • 9 Posts
  • 1 Reply Like
Which workflow are you trying to use? We have three different types of workflows. 
  1. Feedback and Approval
  2. Request List
  3. Custom Workflows 
Can you please clarify? 

Thanks,
Adi
Photo of Jake Henry

Jake Henry

  • 2 Posts
  • 0 Reply Likes
Request List.