BookmarkSubscribeRSS Feed
0 Likes

SAS Visual Investigator has a Conditions Configuration under Relationships. Given the UI placement, and given that it throws out an error that Current User configurations cannot be used under link styles - totally suggests that this configuration is meant to manage the access for each relationship. There are actual use cases as well where in the users will need to see all entities, and only relationships has a restriction. 

 

Below are the points for SAS R&D consideration please:

1. If relationship conditions are only meant for link styles, then please keep this configuration page under views and not have a separate conditions tab.

2. To the users, it was an expectation that we can restrict access to relationships similar to how we can restrict access to entities. Introducing this capability would be great to further highlight the business value of the SAS Solution to the users. SAS is able to provide a lot of analytics and data capabilities - Users expect that SAS is able to meet foundation operational requirements as well to facilitate holistic production usability.

3 Comments
susantrueman
SAS Employee
Status changed to: Suggestion Under Review

Thank you for your product suggestion. The SAS product team are reviewing and will post updates here. 

Thanks, 

Susan

pmvi
SAS Employee

Hi, thanks for engaging in the Communities and for raising this suggestion. We can see how this configuration could be interpreted this way.


1. Relationship Conditions and access control
The Conditions tab under Relationships is not intended to manage access or visibility of relationships.
The Conditions tab is part of the reusable conditions framework used across several areas of Visual Investigator configuration.
As documented here, these conditions are not part of the authorization model.
Identity-based conditions such as “Current User” apply to data object (entity) security conditions, as described here.
So the behavior you’re seeing is consistent with the intended design, and the Conditions tab is not intended to control relationship access.

We’ll continue to review whether additional UX clarification in this area would help make the intended behavior clearer.


2. Relationship-level restrictions
Today, Visual Investigator follows an entity-centric security model, where:

  • Access is defined at the data object (entity) level
  • Relationship visibility is derived from the visibility of the connected entities

We’d like to better understand the requirement around restricting relationships independently of entities.

If you’re working through scenarios where relationship-level visibility needs to differ from entity-level access, it would be helpful to understand the use cases in a bit more detail.


No changes are currently planned for either scenario described above.

pmvi
SAS Employee
Status changed to: Suggestion Closed