When creating a new Business Process in Laserfiche Cloud, the Starting Form Privacy appears to default to Public when the process is first published.
For organizations that have external users in their Laserfiche Cloud environment, I think this creates an unnecessary security/privacy risk.
We create a large number of business processes, and each time a new process is created, the designer has to remember to configure the Starting Form Privacy appropriately. In our environment, we have external users alongside our internal users, so we need to be especially careful that a newly created process isn't accessible to users who shouldn't have access to it.
A form could potentially contain sensitive or internal information, and forgetting to configure this setting on a newly created process could expose that form more broadly than intended.
I think it would be safer if new processes followed a more restrictive default. For example, Laserfiche could:
- Default new processes to Private, potentially requiring the designer to explicitly configure who can start the process.
- Prompt the designer during the initial publish to review/configure Starting Form Privacy before publishing.
I'm not necessarily advocating for a specific implementation, as Laserfiche may have a better approach. The main request is to avoid having the least restrictive option be the default and relying on every process designer to remember to change it.
For organizations that create many processes and have external users in the same Laserfiche Cloud environment, this becomes something that is very easy to overlook and potentially has significant privacy risks.