Permissions and visibility in Ventoo Case Management

Ventoo Case Management controls access on two interlocking layers:

  1. BC permission sets – basic table and page access (see Permissions in Ventoo Case Management).

  2. App-managed security – role capabilities and case visibility, described here.

Role capabilities

Via Case Management Setup → Role Capabilities you control, per role, what a user may do in a case. The model is opt-out: by default all capabilities are granted; clearing a checkbox removes the capability. The matrix shows Roles × Capabilities; a transposed view (Capabilities × Roles) is also available.

Capabilities include, among others:

Capability

Effect

Change Process / Proceed in Process

Change or advance the process.

Add Activity / Edit All Activities

Add activities or edit all of them.

Create Activities from Scope

Create activities from the scope.

Create Cases / Create Engagements

Create cases or engagements from higher levels.

See / Change Customers, Contacts, Service Providers

See or change party groups.

Run Billing

Run billing.

Manage Context

Change a case's engagement/scope (incl. reassigning case ledger entries).

Assign Attributes

Assign attributes.

Cancel Case

Cancel a case.

See Change Log / Case Ledger Entries / Dimensions / Team

See audit and detail areas.

Change Dimensions / Change Team

Change dimensions or team.

The full list is in Enumerations in Ventoo Case Management (Case Capability).

User Party Mapping

Via Case Management Setup → User Mapping, you connect BC users to a party and a visibility level:

Level

Effect

All

Sees all cases.

Team

Sees cases of their own team plus role-based cases.

Own

Sees only role-based assigned cases.

Further per-user settings (excerpt): individual activity date restrictions and the planning-edit permission ("Can Edit Planning").

Materialized case visibility

Visibility is not recomputed on every query but pre-materialized in a table (user → visible cases). On list and card pages, a filter is set from it on open. The visibility rows are rebuilt at every relevant change point: team membership, role flags (Grants Case Visibility), relationships, and user mappings.

Activities, tasks, and relationships inherit the visibility of their parent case.

Teams

A team (Case Team) bundles members for team-level visibility. Cases can be assigned to a team; members with visibility level "Team" see their team's cases. Manage via Case Management Setup → Teams.

Capability-sensitive factboxes

Detail factboxes (dimensions, statistics, party overview) respect role capabilities: they are either hidden by the host via Visible or hide their own groups. Factboxes on standard BC pages (Customer, Sales, Contact) are intentionally outside this system and are governed solely by BC table read permissions.