Skip to main content

Why can a user give feedback to people who do not appear eligible?

Check the feedback scope and the user’s organisational permissions before treating access to additional people as an eligibility problem.

Why can a user give feedback to people who do not appear eligible?

Check the feedback scope and the user's organisational permissions before treating access to additional people as an eligibility problem.

Follow this troubleshooting flow

  1. Confirm the user who can give feedback, the person who appears unexpectedly, and the feedback scope being used.

  2. Open the feedback scope and confirm that it is enabled, is not read-only, and has the intended Feedback Permissions setting.

  3. Check the feedback giver's profile, including backoffice roles, groups, team, Special Permissions, Exclusion Permissions, and Excluded Users.

  4. Confirm whether the person receiving feedback belongs to the giver's team or to a team covered by a Special Permission.

  5. Check whether an exclusion should prevent access. Exclusions take priority over permissions that grant access.

  6. Decide whether the access matches the organisation's intended permission model before changing any configuration.

  7. If you make an authorised permission change, ask the user to reload the platform and test the same feedback scope again.

Why can this happen?

Functional eligibility and permission scope are different. A user may not appear eligible according to one business rule but may still be able to see or act on additional people because their profile grants wider organisational access.

  • Feedback scope permissions control who can submit feedback in that scope, such as team managers, the user themselves, or both.

  • Backoffice roles can grant administrative capabilities beyond a normal user or manager profile.

  • Special Permissions can grant access to another team's data even when the user does not belong to that team.

  • Groups and segmentation can control access to features and modules.

  • Exclusion Permissions and Excluded Users can remove access that would otherwise be available.

For this reason, seeing an additional person in Feedback does not by itself prove that the person's eligibility is wrong.

What should I check in the feedback scope?

  • The scope is the one the user is actually using.

  • The scope is enabled.

  • Read-Only Mode is not preventing or changing the expected interaction.

  • Feedback Permissions match the intended participants, such as Team Managers Only, Self Feedback Only, or Team Managers or Self-Feedback Only.

  • The scope context matches the type of feedback being submitted.

What should I check in the user's profile?

  • The user's team and groups are correct.

  • The assigned backoffice roles are appropriate for their responsibilities.

  • Special Permissions do not grant unintended access to another team.

  • Any required Exclusion Permissions or Excluded Users are present.

  • A recent organisational or permission change has been saved and loaded by the user.

What should I change if the access is not intended?

  1. Identify whether the access comes from the feedback scope, a backoffice role, group membership, team assignment, or a Special Permission.

  2. Confirm the intended access with the person responsible for the organisation's permission model.

  3. Have an authorised administrator correct the specific permission source.

  4. Ask the user to reload the platform and verify that the unexpected person is no longer available.

Do not change the recipient's eligibility, team, or profile merely to hide them from one feedback user. Correct the permission that grants the unintended access.

When should I contact Support?

Contact Support when the feedback scope and user permissions have been verified but the visible population still does not match the configured access. Include:

  • The feedback giver's user identifier and profile type.

  • The feedback scope name and its Feedback Permissions setting.

  • The relevant team or organisational unit, without sending unnecessary personal data.

  • The Special Permissions, exclusions, or groups you checked.

  • One example user identifier that appears unexpectedly.

  • Whether the permissions were recently changed and the user reloaded the platform.

Continue troubleshooting

Did this answer your question?