You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CiviCRM活动权限设置咨询:如何禁止用户查看其他用户的活动

Restricting Users to Only View Their Own Activities in CiviCRM

Alright, let's break down how to lock down activity visibility so users like Felix only see activities that belong to them. The default CiviCRM setup doesn't have a one-click toggle for this, but we can combine core permissions and CiviCRM's powerful ACL (Access Control List) system to make it happen. Here's a step-by-step guide tailored to your scenario:

1. Strip Away Overly Broad Permissions

First, we need to make sure Felix (and other restricted users) don't have permission to see every activity in the system:

  • Navigate to Administer > Users and Permissions > Permissions (Access Control).
  • Find the user role assigned to Felix (e.g., "Authenticated Users" or a custom regular user role).
  • Remove the view all activities permission from this role—this is critical, as it overrides any more restrictive rules we'll set later.
  • Keep the view activities permission enabled; this gives users base access to activities they're allowed to see, which we'll narrow down next.

2. Build a Granular ACL Rule

CiviCRM's ACL system lets us define exactly which activities a user can view. Let's create a rule that ensures users only see activities they're directly associated with:

  • Go to Administer > Users and Permissions > Access Control Lists (ACLs) and click Add ACL Rule.
  • Fill in the basics:
    • Name: Something clear like "Restrict users to their own activities"
    • Description: "Users can only view activities they created, are assigned to, or are linked to as a contact"
    • Status: Enabled
  • Now set up the access constraints:
    • Type: Contact (since we're linking the logged-in user to their own contact record)
    • Operation: View
    • Object Type: Activity
    • ACL Entity Role: Select Felix's user role (the same one we adjusted in step 1)
    • Contact Relationship: Choose "User and Contact"—this ties the rule to the logged-in user's own contact profile
    • Permissions: Check the "View" box under Activity permissions
  • For extra strictness (if you only want users to see activities they created or are assigned to, not just linked contacts), use the advanced criteria:
    • Expand Advanced Options
    • Click Add Criteria for Activity
    • Add two conditions with OR logic:
      1. Created By equals Current User
      2. Assigned To equals Current User

3. Test the Setup

Log in as Felix and head to Activities > Find Activities. Run a search—you should only see activities where Felix is the creator, assignee, or linked contact (depending on your ACL setup). The Phone Call created by JohnDoe, assigned to Barnie, and linked to Danielle should not appear in Felix's results at all.

Quick Bonus: Lock Down Contact Access (If Needed)

If you want to make sure Felix can't stumble on the activity via Danielle's contact record, double-check that his role doesn't have the view all contacts permission. Instead, use view my contacts or a similar ACL rule to restrict contact visibility too.


内容的提问来源于stack exchange,提问作者Harkedian

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 09:38:28