Mark the message content of an inbound email as containing PII
Help Desk Agents with the appropriate permissions can now edit existing messages to remove personal information that may have been accidentally included or is no longer needed. In this release, this previously released feature is expanded to include inbound email messages that were previously excluded.
When a Help Desk agent recognizes that Personally Identifiable Information (PII) has been included in a Help Desk message whether inbound through the web or through an email channel, they can now mark the message as containing PII.
A manager with the appropriate permissions can then edit the message, and unmark the message so that it is no longer flagged as containing PII.
This feature can be used to remove personally identifiable information from long-term storage in the database, reducing risk of misuse, and helping with compliance.
Steps to enable and configure
If you are already using the web messages feature to redact PII, no changes are required.
To enable the feature that allows editing of messages for the first time:
- Turn on the profile option:
- Go to Setup and Maintenance.
- Click on the Task Icon.
- Click on the Search link.
- Search for Manage Administrative Profile Values.
- Search for the Profile Option Code for the type of Help Desk:
- HR Help Desk: ORA_SVC_HRHD_ENABLE_MESSAGE_EDIT
- Internal Help Desk: ORA_SVC_ISR_ENABLE_MESSAGE_EDIT
- Set the Profile Value to Yes.
- Click Save and Close.
- Click Done.
This will allow agents to mark messages as containing PII.
2. Create a new custom job role.
Create a custom job role or edit/add to an existing custom role using the instructions found in the Securing Sales and Fusion Service guide. You will need to add the appropriate privilege as indicated below.
- For HR Help Desk, use Edit HR Service Request Messages (SVC_EDIT_HRHD_MESSAGES)
- For Internal/Operations Help Desk, use Edit Internal Service Request Messages (SVC_EDIT_ISR_MESSAGES)
Assign this new role to whomever should be given the permissions to edit the messages. This can be done while creating the new job role, under the Users step, or you can assign the role to individual users after it is created.
Tips and considerations
Agents should only mark the message as containing PII after the information is no longer needed.
To assist editing managers/agents in finding those message that need to be edited, an OTBI analytics report can be created and scheduled to be sent regularly when a new request has been marked as containing PII.
Key resources
Refer to the original instructions here: Oracle Help Desk Cloud 24A What's New
Access requirements
To configure this new feature, the administrator must have access to the Security Console and Setup and Maintenance.
Help Desk Agents are given permissions in the out of the box job roles to be able to mark the messages as containing Personally Identifiable Information (PII).
Whomever will be given the permissions to edit must be granted access to a custom job role that includes one of the following privileges:
- For HR Help Desk, use Edit HR Service Request Messages (SVC_EDIT_HRHD_MESSAGES)
- For Internal/Operations Help Desk, use Edit Internal Service Request Messages (SVC_EDIT_ISR_MESSAGES)