We have a requirement to restrict a particular Business Workspace in ECM if an Entity is restricted to a specific user by the Admin. For this requirement, we tried
- Add/Update Access for the User to restrict access to that particular Business Workspace. But,
- when we did that, the user could still access the Business Workspace because the Role assigned to the User has access to the Business Workspace.
- Also, we cannot restrict the owner of the Business Workspace, if the owner himself is blocked access by the Admin.
- Use Supplemental markings on both User and Business Workspace Folder. But,
- The Supplemental markings work when both the User and the Business Workspace folder has the same marking, So if we have COI for a User(who is a Manager) we will have to add the markings to all the users in the Manager Role except for the COI User and thereby restrict the user. But even here we will have the same problem, where a new user is added to the Manager Role, they would still not have access as the new user is not marked with Supplemental markings.
- We will have to Add/Remove Supplemental markings to Folders and Users on the Fly which would need ECM services that don't seem to be available in the Document.
- The Owner of the Business Workspace cannot be blocked - So, if the Entity is blocked via COI/Ad hoc to the one who created the Entity, it wouldn't work.
Is there an easier way in ECM, where I can restrict a particular user even if his role has access to the Folder?