---
sourceDocument: Xanadu Employee Service Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/xanadu/employee-service-management

 Release :

    - xanadu

ft:locale :

    - en-US

ft:publication_title :

    - Xanadu Employee Service Management

ft:clusterId :

    - emplsm

bundleId :

    - emplsm

workflow :

    - Employee


---

# Configure an employee relations case restriction

# Configure an employee relations case restriction {#ariaid-title1}

* Release version: Xanadu
* 
* Updated August 1, 2024
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Define what groups can view or access employee relations cases using Case Restriction
Configuration.

## Before you begin

Role required: admin and sn_hr_er.admin  
Warning:  
When creating case restrictions, be sure that you have at least one configuration that enables you to read these cases.

## Procedure

1. Navigate to AllEmployee RelationsAdministrationCase Restriction Configuration.
2. Click New.
3. On the form, fill in the fields.  
   {#hr-er-create-case-restriction__table_hzl_qtx_zkb__entry__2}

   | Field | Description |
   |-|-|
   | COE | Center of Excellence (COE) that you want to restrict access to. Note: For more information on COE, see [HR Centers of Excellence data model](https://servicenow-prod.fluidtopics.net/6_ZY9CwTN5l0t3hnHxqbJg "Organize HR data, services, and processes by functional discipline with the HR Centers of Excellence (COEs) data model."). |
   | Able to restrict cases | Option to enable members of a group to restrict access to all HR cases for the COE. |
   | Able to view restricted cases | Option that enables a group to view restricted HR cases for the COE. |
   | Application | The application that the case restriction configuration applies to. This field is automatically set to Human Resources: Employee Relations. |
   | Active | Option to activate the case restriction configuration record. |
   [Table 1. Case Restriction Configuration form]

   {#hr-er-create-case-restriction__table_hzl_qtx_zkb}
4. Click Save or Submit.
5. Add the groups that you want the case restriction configuration to apply to.  
   Note:  
   You can also restrict by role. Agents with the sn_hr_er.confidential role can access restricted ER cases.  
6. Click Update.  
   Note:  
   Collaborators on an HR or ER case can override COE security. But, ER cases with restrictions override collaborators. For more information, see [Create COE security](https://servicenow-prod.fluidtopics.net/4yGTflv2NGovYQVwyD4XCw#configure-hr-coe-security "Place security on a COE to prevent a group from accessing another group's cases.").

   COE security policies are a way to easily restrict access to different COEs via configuration. The underlying COE security policy implementations are [ServiceNow ACLs](https://www.servicenow.com/docs/access?context=access-control-rules&version=xanadu&pubname=xanadu-platform-security&ft:locale=en-US).

*[\>]: and then


