Default record rights must not grant delegation to a company-wide role
- Risk
- High
- Evidence
- metadata
- Section
- Access controls
- Fix shape
- entity · Object
Absent, it prevents detection, investigation or response.
Decidable from the instance’s own configuration.
Who may read, create, change and delete each object.
One task per non-compliant object.
Maps to ISO 27001SOC 2
Control Statement: Default rights on new records must not grant the “Allow and grant” right level to a role that reaches the entire organisation.
Description: Creatio’s default record rights determine the access automatically applied to every new record of an object, expressed as a grant from an author role to a grantee role for the read, edit or delete operation. The right level may be “Deny”, “Allow”, or “Allow and grant”. “Allow and grant” additionally permits the grantee to extend that access to others. Where the grantee is a role reaching the whole organisation, every user may widen access to these records without administrator involvement.
Rationale: This is a privilege-escalation path that leaves no obvious trace. “Allow” and “Allow and grant” sit adjacent in the same picker and read almost identically, so the stronger option is frequently selected without intent. The result is not merely broad access — it is the ability for any user to grant access onward, so the effective audience of a record set can expand continuously while the permission configuration itself appears unchanged. Reviewing the object’s configured rights will not reveal who has been granted access in practice.
Audit Procedure:
- Identify the organisation roles at the root of the organisational structure — those with no parent role.
- Open System Designer → Users and administration → Object permissions and select an object administered by records.
- Review the default rights configured for new records.
- Record the object as non-compliant where any entry grants “Allow and grant” to a role identified in step 1.
- Repeat for every object administered by records.
Remediation:
- For each non-compliant entry, determine whether the ability to delegate access was intended.
- Where it was not, change the right level from “Allow and grant” to “Allow”.
- Where delegation is genuinely required, grant it to a specific role rather than a company-wide one.
- Review records created while the setting was in force, since access already delegated is not withdrawn by changing the default.
Default Value: Creatio applies no default record rights until an administrator configures them. Where they are configured, the right level must be chosen explicitly; Creatio does not warn that “Allow and grant” confers delegation, nor that the selected grantee role reaches the entire organisation.
Cite this control as CSB-ACS-003, Security Benchmark v0.5.0. Verified against
Creatio 8.x. Published by ctx10; not
affiliated with or endorsed by Creatio.