- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-27-2020 04:54 AM
Dear Community Folks,
We have a requirement in SecOps SIR module as below
The Requirement is focused on the Knowledge article in SecOps Module in Security Incident Knowledge base where we have below conditions
- Only the user with knowledge_admin and sn_si.analyst should be able to create the knowledge article under the knowledge base Security Incident
- And once the Knowledge article is created there should be an approval triggered for the knowledge article that can only be approved by user with role knowledge_admin and post which the KA has to be published
- Post the knowledge article is published the KA has to be viewed by any user who has SN_basic rule
No customization script can be allowed as we need go with only configuration and OOB components.
User Criteria under knowledge articles was used to achieve the points 1 and 3.
But with the Point 2 we see that when the Knowledge article is created by SN_analyst there is no approval triggered and Sn_analyst itself can approve/Publish the Knowledge article which should not occur.
I need your help in triggering the approval for the knowledge article and restricting the sn_si analyst to self-publish the knowledge article.
Thank you for going through the article.
Regards
Satya
Solved! Go to Solution.
- Labels:
-
Security Incident Response

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-28-2020 07:36 PM
You may have some luck navigating to the Knowledge Base record for Security Incident Response, and adjusting the `Publish Workflow` choice.
Baseline it is set to instant publish, and you can test swinging it to "Approval Publish".
However, I think that will send an Approval to the Owner / Manager of the Security Incident Knowledge Base - which probably is a good route.
You may need to perform additional configuration if you want that approval to go to users with a specific role.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-28-2020 07:36 PM
You may have some luck navigating to the Knowledge Base record for Security Incident Response, and adjusting the `Publish Workflow` choice.
Baseline it is set to instant publish, and you can test swinging it to "Approval Publish".
However, I think that will send an Approval to the Owner / Manager of the Security Incident Knowledge Base - which probably is a good route.
You may need to perform additional configuration if you want that approval to go to users with a specific role.