Skip to main content

#DocuSign Status0 discussing

Hello! We are enabling DocuSign eSignature for Salesforce at my organization. We provision some users with a DocuSign login, and some users with a Salesforce login, both using Okta SSO. DocuSign user permissions are managed in the DocuSign application.

 

When enabling eSignature for users, we want to leverage eSignature's permission set method, which is recommended for SSO use-cases and for when users already have permissions in DocuSign. We would assign all users with the "DocuSign Login" permission set. Then, when a DocuSign user is in Salesforce and they interact with a component or button for eSignature, they are prompted to provide their DocuSign credentials. (See https://support.docusign.com/s/document-item?language=en_US&bundleId=izj1586134369853&topicId=nqk1629408501542.html&_LANG=enus)

 

We tested all of of this and it works great. However, we have one issue. When users self-authorize, the "DocuSign Login" permission set is revoked and the "DocuSign User" permission set is provisioned. This is expected functionality of eSignature. However, the "DocuSign User" permission set grants access that we can't restrict.

 

Users are able to circumvent our sharing model due to these additional permissions. For example, a user could click on "View Envelopes" on the "DocuSign Envelope Status" component on a record page, and that navigates them to the "DocuSign Status" recently viewed List View. The user is able to see all "DocuSign Status" records. Further, they can view what we consider confidential information by adjusting the fields displayed on the list view, such as the related Account and the Subject Line. We have confidential records in the system and not all users are supposed to know these Accounts or people are in our database.

 

When we contacted DocuSign support, they said we could clone the "DocuSign User" permission set, revoke it from users, and replace it with our cloned permission set that has the appropriate permissions. They flagged that this cloned permission set would not be supported by them and that it is not the recommended practice.

 

I ran a quick test to see if the cloned permission set method was viable, but unfortunately once I removed the out-of-the-box "DocuSign User" permission set assignment from a user, that user received an error on the "DocuSign Envelope Status" component, stating they need to have the "DocuSign User" permission.

 

Has anyone implemented a more strict sharing solution for DocuSign eSignature for Salesforce while also still being able to leverage the DocuSign SSO methodology? Or did you have to switch to provisioning users via the eSignature application's "User Management" tab?

 

#DocuSign For Salesforce #Docusign #DocuSign Status #DocuSign ESignature #ESignature #Permissionset 

How Do I Modify eSignature's

1 answer
  1. Nov 23, 2023, 1:56 PM

    Sorry for the inconvenience. In case you don't receive a response here, may I also suggest to contact DocuSign Support Team to get additional assistance on this.

0/9000

How to display Template Name in DocuSign Status object in Salesforce?

2 comments
0/9000