That is the question. I am afraid that the decision not normal, but can someone tackled and found a workaround?
Say there is a CMDB with configuration items of various classes and geographically distributed. They, of course, serve by the local groups, as a first level tech support. So they can watch and update information on their CI they should be in a group - itsm-configitem and have the rights -rw. But then they have access to all CI's. The group itsm-configitem have no links to the location of CI.
Question:
How do I restrict access to CI's, they do not serve?
