Skip to main content
Question

The effective rights of a user group in our test environment's IAM differ from what I set in the SF.

  • April 14, 2026
  • 2 replies
  • 20 views

SanderAdam
Captain
Forum|alt.badge.img+5

Hello everyone,

I run into an issue regarding roles and rights. We have a few key roles that need to be restricted a little more, so I set the details of a certain table as the following:
 

And this is how it is in the IAM on the user group in question after a sync to IAM:

The rights are fully open, while I set it quite differently in the SF part. Now a user gets to see tables they shouldn't see. Is there something I am overlooking or is there something wrong?

2 replies

I assume in the sf you are looking at the role, and in IAM you are looking at the group? Does the user have another role that gives access to the other details?


SanderAdam
Captain
Forum|alt.badge.img+5
  • Author
  • Captain
  • April 14, 2026

I think that is correct, I checked the user group and the user itself and it only has the role I am checking in the SF assigned. All is assigned as we expect it. But somehow it has more access than the user in this user group or role is supposed to have.