For the complete documentation index, see llms.txt. This page is also available as Markdown.

Restricted Portfolio Management and Fulfillment

Until now, anyone with Portfolio Manager access could manage the complete Service Portfolio. That works while one team owns everything, but it becomes limiting as soon as different departments look after different products.

Two restricted permissions let you delegate that work in slices. A specialist team can manage its own products, or process its own orders, without gaining access to everything else.

Restrict portfolio management to selected products

Setting this up takes two steps, and both have to be in place before anyone gains access.

1. Assign a managing group to the product

Each product can have a group assigned under Responsibilities → Management. This group defines which organizational unit is responsible for managing the product.

You could assign monitors to your IT Procurement group, for example, while mobile phone products are managed by a different team.

Responsibilities section showing the group assigned under Management.

2. Grant the Restricted portfolio manager permission

The employee also needs the Restricted portfolio manager permission, which you enable in their permission settings.

Employee permissions with Restricted portfolio manager enabled.

Access is granted only when both conditions are met: the employee belongs to the group assigned under Management, and holds the Restricted portfolio manager permission. If either is missing, they cannot manage the product.

Working within a restricted portfolio

Employees with this permission see a Service Portfolio containing only the products assigned to their Management groups. Within that scope they can view, create and manage products as usual, without reaching products managed by other teams.

Service Portfolio view limited to the products of the employee's Management groups.

Removing the permission or changing the Management group removes the employee's access. Products they created or edited earlier stay in the Service Portfolio.

Delegate fulfillment by group

Fulfillment works the same way. Under Responsibilities → Fulfillment you define which group is responsible for processing orders related to a product.

Responsibilities section showing the group assigned under Fulfillment.

Again, both conditions apply. The employee must belong to the assigned Fulfillment group and hold the Restricted fulfillment user permission.

Employee permissions with Restricted fulfillment user enabled.

When both are in place, the employee gains access to Order processing for the relevant products. They can work with the corresponding internal fulfillment orders and update their status during provisioning. Orders for products assigned to other Fulfillment groups stay out of reach.

Availability

Restricted portfolio management and restricted fulfillment are available in customer environments, including managed and standalone customer environments. They are not available in supplier environments.

Was this helpful?