Setting Up Application Services
As described under Access Rights, you can prevent unauthorized users from accessing cases. The following points describe how to implement this type of security:
Create an application service for each case type that needs to be secured
Create an action on the application service for each status you need to secure
Link the valid user groups to the application service and define which actions they can perform
Define the application service on the case type
Define the related action for each status on the case type / status