HyphaApp / hypha

Submission management software for open calls
https://www.hypha.app
BSD 3-Clause "New" or "Revised" License
68 stars 38 forks source link

Hide tax forms/banking info from staff, only showing finance/admins #4119

Open wes-otf opened 3 weeks ago

wes-otf commented 3 weeks ago

Today finance had requested that sensitive forms like tax forms & banking info when uploaded in the project documents only be visible to them. It would be nice if PMs and other staff could still see that status (uploaded/not uploaded), just not the document itself.

frjo commented 3 weeks ago

Make sense. We should add a setting for this. By default I think staff should see it but with the setting it can be hidden.

Most organisations are far smaller than OTF and the same person does many roles.

frjo commented 3 weeks ago

Or we add an optional setting to the contract document categories to restrict permissions.

frjo commented 2 weeks ago

Add a setting to Wagtail admin "Contract Document Categories". Each category gets a checkbox to restrict document view access from staff. Staff should see that a document has been uploaded but not view the actual document.

frjo commented 2 weeks ago

@wes-otf Contract and Finance always need access to these documents I assume? Finance has no access today but should I think, if it is banking info e.g.?