logo

NJP

Inside the Barrel - ServiceNow Data Filtration

Import · Aug 25, 2022 · video

hello and welcome to another episode of inside the barrel where uh dory and i tackle the day in a life of servicenow admins and developers been a yeah since uh you've done that intro you're almost forgetting what we're gonna say oh my gosh yeah right you go a few weeks without doing an episode yeah can't remember anything i'm really excited about this episode um mostly because uh creator toolbox already did an episode so shout out to the to that team with chuck and earl even though i don't think earl was actually on this one and lauren um where they they really kind of are really advancing the security of uh of servicenow or at least the administration of the security yeah i think you know data filtration makes it just that much easier i mean okay point of view for me as a developer when someone says oh hey we need to create some acls you know what i do i go do i have to oh gross and if i'm just prototyping stuff guess what i don't do i don't create any or any of that stuff because it's such a pain in the butt but now with data filtration it's so much easier even i can do it i i feel like the last like release in this one they talk about like adaptive authentication where it's really focused on where the subject is like aka the person logged in or the person doing that action or what they're doing or what access they have in order to determine um you know how to approach and like that's even exciting with and it's they're using shared code between their like sso as well so like you'll now be able to do like if this ip is like logged in then they have access to you know a certain record right yeah yeah that's something you couldn't do before right yeah yeah the granularity there and and from what i can't remember his name but the the other guy that was on that uh show maybe the product owner he was talking about you know this is mvp currently and so there's more changes coming um and uh and so i think that may get built out more you know but beyond just uh the ip address and a couple other things they have currently listed um but it's neat to see the granularity they're offering in being able to really restrict down um you know viewability of records and so forth i think it's pretty cool yeah and i think um i think i can see the future where it's like now we're talking citizen developers and i know you need security admin to do this right now but in the future like if it's in your app and you have that delegation admin like now you can then also control where you couldn't control that before yeah yeah so yeah and like i said you know a person like me who i probably would for the platform side is more citizen developer than anything else it just makes it so much easier because it's it's and i think he mentioned this it's readable you know it's it's understandable from the get-go it's not like an acl where you're like uh how does this work yeah what do i have to do the amount of times i read that chart of like you know when does things get access or not like it's just well and then and then you have to follow the flow down right what is it um oh you know it's like record uh field you know it's this whole hierarchy that you have to know this is how this is showing how bad we are is security happens you know i really try to not touch acls like yes ever right like if i had to touch an acl for surveys actually and i was like man i can't wait for data filtration because that's like a prime example of like i don't need to build an acl for this um and i could do data filtration for it yeah i agree because i think a really good use case here is around surveys like if you think about there's so many different people in the company that may want to run surveys in servicenow and like if you give them survey admin access to go and modify a survey and it's it's relatively easy to to do so but like then you give them access to all of your surveys and so like this is like the instant easy use case i can think of like i only want this person to see their survey and i only want this person to see their survey yeah yeah sure from an administration standpoint right yeah the implications are are huge you know being able to really segregate data from other people right but i think we wanted to go a little bit further because there is one there's one drawback with with data filtration right there's that and this something this is something that comes up quite frequently when you are doing uh different methods of security you get that message x number of records hidden due to security constraints nobody wants to see that yeah it's so funny it's like nobody like i haven't found a single client that's like oh i like seeing that message what's this message i don't like it people shouldn't know yeah this is no good yeah um and that comes from so if you're doing uh what is it uh acls it's because it's uh it's it happens after in in the line in the hierarchy of how things are processed so it's it's like part of the last thing yep totally it was it was definitely an architectural decision where it's like we want to before the query happens do some things remove some records then pass it over to the query and then pass it over to an acl to make sure that you know they they do or don't have access and the acl is like that last line of defense and they decided to put a security message there and you know like this is so long ago but like all they had to do is only show that security message if you're an admin and this thing would have been like you know never i think i think it should be a configuration item show security constraint message or don't show you know it's like i get why you need it because at some point if you're an admin trying to debug you have no idea right like what's going on and so right now right but right it sounds like you know speaking of debug it sounds like they've really made it with with data filtration they've really made it um very debuggable right if you're using that new debug screen um it really i mean unlike the error messages of yesteryear it actually tells you what's happening yeah yeah yeah it's so nice service now it's definitely a new mindset it seems like when they're building new platform features to really make it everybody's lives easier and i'm assuming it makes their lives easier so hopefully yeah right it's good yeah so let's let's uh let's dive in so the or before we dive in like let's so what we don't want to do is recreate the content that the right the creator toolbox uh people did so we'll put in the description of this you know link out to them really awesome they spend an hour they have a product manager in there like super detailed for anyone that wants to know the the back end behind it or even the context of why it is but one of the limitations that they talked about is um the that security constraint message is still there so what john and i were thinking is why don't we try to automate uh creating a business query based on a data filtration so we have no idea if we'll get how far [Laughter] we may give up halfway i don't know um but i think that would be just like a little fun activity to to try to dive into some of the before query rules so you get an idea and they do say that this feature will eventually be supported so you don't have to do this so this is more of like a temporary fun activity stop gap yeah yeah yeah yeah i'm glad they talked about that that they you know in future builds they are very cognizant of data filtration still being towards the end of the hierarchy where they want to be able to either give you a choice to run it like a before business query or still back at the end so i think that's kind of neat that they're you know they really are thinking ahead on some of these new uh features that they're offering yeah totally and it was we got a tidbit that was really interesting about glide record and glide record secure i don't know if you if you remember that conversation i i remember there were some comments about that if i remember correctly yeah they went down the rabbit hole of like why isn't everything glide record secure and the nuances there and it was like you know like at some point somebody needs access to read the thing and it's just so co-mingled that it was just like yeah all right we can't solve this one did they i can't remember if they mentioned it or not but there was something about admins also right that they're um they they because you can you know if you do maybe i'm miss remembering how this works oh well we'll we'll ignore that for now we'll move on and get into the meat of this i also want to say john it's so like clean behind you like it's so organized like that bookshelf looks amazing that's only because you can see at this oh oh see there's a desk that's just messy that's that's my wife's desk so i i try to stand in front of that that's nice and you know i i like the wallpaper behind you that is like what is that art decoy 90s art decoy 80s art decoy yeah i'm actually in a hotel so it's uh it's not my wall unfortunately oh where are you uh i'm currently in poland actually poland wow mr traveler over there what are you doing in poland uh so crazy story i ended up in poland you know hitchhiking now um so there i was um you know i think we talked about it before there's the whole cta certified technical architect program where you're with a cohort for you know six months or four to six months and you're assigned a team and actually one of my old team members from that cta program is getting married in poland neat neat that's pretty cool so there's actually a three or four of the the cta folks here that we're gonna get to hang out and and chat again so it's it's been a really cool experience that like not only do you like get to work on your you know cta and gather a lot of experience you actually get to meet really cool people that are interested yeah and being friends afterwards as well you know it's what i love about the servicenow community i i miss like i haven't been to a knowledge in a few years but i miss that you know kind of community that you get you you start meeting people and you become like fast friends it's like all of a sudden everyone's like dude let's get together and do this or do that or whatever it's it's just pretty cool i can't wait till i can get back to one i love that someone came up to me at knowledge and was like oh you're dorian and i was like what whoa i was like i'm like i don't know you oh yeah yeah for sure all right let's jump in let me share my screen uh let's see there we go all right um okay all right so i've installed the plugin um we can uh verify that if i look for data filtration there's all my stuff and uh so we're gonna start with roll because that one's like the easiest one um and and i think in the future or i think the way this will be used more is definitely that subject criteria so you're creating like a grouping of things so that someone's in a group and a role um i definitely think that's like the complexity you'll get for flexibility you'll get with that um right for us i think starting on roll filter to kind of show it is definitely the way to go and you've already elevated i'm assuming since you oh you know what good call there i have not and i guess you don't need elevate to create the criteria but to use it you will so oh yeah what do we want to call this so i mean the fun ones that i like to play with is incident right like we you probably have incidents in your demo incident so like let's let's play around with like hiding incidents if you don't have a specific role right like we could we could we could name it whoever [Laughter] if you don't have survey survey role survey reader role all right let's see here just uh because we were talking about service either perfect okay so we are looking for which one you want survey reader survey reader okay and it's interesting so what you're doing with these like roll filter criteria this is actually what you would use to combine them i actually don't think you need to do this for just a one-off one so like if you go back to all and and go to your data so like this is useful if you want to combine things in the subject criteria um but if you just wanted to create like a very basic one you wouldn't need to so if you click click new here so just um survey reader uh restrictions i think it's actually the opposite but it's okay just for this um just to kind of show that like under the inputs if you click edit here you'll see that your option is is there now so that's like this is where you would you would be building the kind of like reusable components using that right for for our simplicity we actually just need to go to um all and then just go to the data filtration records just the top one and we'll just create a new one and we won't need to actually use that subject criteria in this case so that's definitely you know i i wonder if they'll make that experience a little bit better um on like when do you create criterias and subject criterias versus just putting it right into the data filtration i i'm hoping that you know like you said this is a new mindset on on feature building and they take into consideration feedback you know what i mean and so i'm hoping that you know they can do that and say hey you know what we've gotten feedback here that that people are really uh interested in having things laid out a little easier for us to understand and stuff like that and can incorporate that in i think that would be really really neat by the way someone messes something in chat but i can't actually see it john so maybe oh well let's see what they wrote and it's a hot oh yeah it's actually touch this is one of my favorite features nice i think for admins this is going to become huge honestly you know 100 agree yeah let's go to incident let's do the table on incident so we're going to oh that's it yeah just because that's like the easiest to kind of demonstrate okay so under so let's say you can the description could be you can only see incidents if you have survey reader oh my gosh i'm terrible and maybe it's like you can only see active incidents we'll we'll make it a little bit more robust only see active incidents and this is oh no i remember i remember uh chuck saying this was a very short uh description if i'm then they'll probably change that before ga like i think that's such an easy change for them like but yeah maybe not okay so um so now that we have our description if we look at our data field so users that uh do not satisfy the subject condition will be denied records matching this okay so we want to say that active is true and yeah so that means that if the subject because and again this is like kind of weird to think about and i think chuck mentioned this as well like if you don't match the subject condition then you will deny be denied seeing these records so if you do match the subject condition so we'll talk about the subject condition then um you get access to see this oh right i think they did mention that they felt these were backwards too because when you read it out or when you say it out loud right subject condition well you haven't gotten there yet because you've been working on this guy yeah and i think they did it because they wanted to follow the layout of acls which talks about the data first and then rules but right questionable cool so for the subject condition so now we're so going back to our description we want to do the subject role is from a survey reader okay and let's uh deactivate this real quick just to kind of show that we can c records and then when you activate it you don't see records kind of thing yeah have you noticed pdi's are a bit slower than normal as of late i just i i don't know it's all the all every other time right and and you don't have survey read a role i'm assuming as an admin so i think uh yeah i don't know that i do there is no admin override so this should so if you go to the incident table or have another tab for the incident table the chuck's team playing this way better than we did because they had like impersonators all over the place i know i was just thinking about like man how am i gonna do the impersonation piece maybe we skipped that but i even mentioned that you shouldn't impersonate because the concept oh that's right because it it it doesn't it causes problems and it doesn't it doesn't uh yeah you can't it it will follow the security based on the originating person so yeah you can't impersonate you actually have to log in and i think it's actually quirky i think sometimes it does that so we can we can show that so if you did you show incidents or yeah what yeah well there we go okay so you see no security constraint or 73 great let's change let's go back to that tab activate this you don't have survey read or roll assuming and refresh if i still see 73 we can go check the user and see what uh let's see what i have all right still so maybe this won't work for for admin because they kind of contain everything oh well you know i'm i'm also elevated too i wonder if that causes a problem well we don't want to add i love the elevate so let's let's just impersonate somebody evil or your classic able he won't have survey reader and we'll see if if that experience is there all right you could do it on this one unless you wanted to do it on are you in like another view well i was just trying to think if there'd be an easy way to handle that but i don't think there will be yeah it's fine i could go create accounts behind the scenes and do it if we need so let's go to our famous incident table no records but it's not because of that rule though because we should we should see a message if it was correct yeah so let me let me see if i can help in the behind the scenes and give people roles for us think i have access to your instance somewhere but i also have like a million instances up so oh i know yeah so maybe go give give somebody a roll and i'll also try to do it uh for you as well who are you going after i don't want to hit the same person i won't i won't go after abel you're not going to hit him i'll i'll go after troy mccoy that name sounds fun that is a fun name troy it's almost like troy mcclure you may remember from oh no but make sure you remember that password in case we don't want to impersonate them oh i didn't i don't okay i'll have to set one in just a second am i studying this guy to survey give him survey and i'll just set the password for uh people all right actually so the password on i you know i do not i mean this password thing look at this i mean look how big that is yeah yeah what who i'm currently not looking at you but i know exactly what you're referring to well it's like you know you message in an architect you're like hey i need access to this instance and they send you your username and then this like four million long character and you're like holy cow i actually just don't like this experience you click the generate and it's a green message but the green message didn't do anything for you yet it just said that you generated this crazy long password and then you still have to click save yeah seriously and if you forget to copy before you click save you got to redo the whole thing right so there's definitely some paste that password somewhere save it okay so i gave abel able didn't have the itil rule so i'm giving abel the itil rule so now uh i will go impersonate able while we while you're doing that and see so now able should have c incidents because he has itil and but he should get the security constraints nope oh yes cool so abel has security constraints now so if you want to show that or i can i could do a screen share of that yeah maybe you should do it real quick just so it'll be yeah let's there we go share screen i just gotta make sure it's the right one it's in this video there we go yeah so and he's starting to get some security constraints right so that's the message no one likes yeah and if i click on these these are probably or if i show on the columns by the way just shout out smtools this is like my favorite button i click all the time to like show all of those extra columns like you do that all for me like awesome like love that feature yeah i have come across some client instances where their column choices are odd to say the least if you get in there you're like what are all these like why do you have all these weird columns listed and you see here that these active is false right so that that means that our our thing that we were we were doing before is working right because all the he needs essentially you need to have survey reader role to see active is true so and you you gave survey reader role to someone else troy mccloy troy yeah there we go so let's try troy and he also has itil at least right uh no he well you know what did he get uh no he does not have eye too yeah so he's not going to be able to see anything here let me give him let me give him my tail real quick oh man all right now he's got itil troy mccoy not troy mccoy this one right troy mcqueen yeah troy mccoy um now let's go into incidents get rid of all this stuff because yeah so yeah he gets to it he sees them all yeah yep so cool so so now let's see let's try to tackle since we've just showed what creator toolbox has done in a longer way let's see if we can try to convert let's create a business uh before business query rule for this the thing that we just did yes so and then we'll talk about automating it um so what you want me to share you want to share it's up to you doesn't matter how you yeah how about you share okay all right all right cool so now let's go into uh your business rules so all business rules and system definition one again so for those who have never created a before query you're going to click new and you're going to click advanced check when that loads [Laughter] when and if it loads then you feel like did i actually click it what happened there we go there you go running yeah that is so slow yeah it doesn't it doesn't like you today i thought it was no it does not probably doesn't like you being logged into it from somewhere else so that's right so advanced now let's name it up top name this uh hide active incidents from survey reader from from hide active instance from non-survey reader i'm already like yeah cool table is incident showing your name and coincidence yeah don't like i told you if i if if i don't uh if i don't come up with the name quick i'll spend way too long trying to come up with the name okay so then we want to check the query and now we want to say so when does this run um what did we what did we do on our it's like active active is true yes and then we look at this and say if your role right yeah but i don't think you have access to do that there too so pretty much all uh all of these are all business before business query rules have to be scripted which is why data filtration is going to get popular yes um so if we go into advanced so this is where it's kind of like so remember we want to hide active incidents from people that don't have the rule right that don't have the survey role so the first thing we do is an if statement to check if they have the role so maybe like yes that has rule yeah oh that death is in my way did they uh deprecate has roll exact do they get rid of that uh i think that's only used on the front end really but i could be wrong yeah well if anybody out there knows off the top of their head please let us know i don't remember because i haven't seen it but i know that has roll unless they've changed it you can't maybe they added a is there another parameter to deal with admin that's a that's a deep dive for something else all right so let's do another statement there so if the survey reader so if they don't have this role i think we have to do the negative of this right so if they don't have this role then and the way query rules are is you have current and you want to essentially append the query that you care about to it right so it'll essentially be like current dot add encoded query and then and then this is what you're um preventing so can we cheat here and and look at it i don't know if you're going to see this but it'll be a little different there right because it'll be subject role but under the data filter and this is where it's going to get complicated because the data filter is going to say active is true it does say active is true but what i was looking at yeah and i was looking at the so that comes off the so that's our that's actually this piece here huh uh-huh so yeah we'll we'll get to that um so current.add encoded query so we want to active equals false and so and i'll walk we'll talk about it or sorry let's do active is not equal to true because that's going to be easier to manage oh my gosh what is that one is that the exclamation point yeah true because that's what the query filter says right first the query filter says active is true and we care about the reverse of that it says yeah the uh well the data can condition or no i'm sorry well it's it's part of data condition it comes out looking like um oh my gosh where am i here this is what the data condition looks like in perfect um the xml and this is kind of the cheat i was going to bring this up earlier but you can go look at those um you know the any condition builder translates to an encoded query string it's it's a great little hack to know that if you're dealing with um condition strings a lot of times all it does is just and them along and you just like if you have to go because i remember one time i had to i had to build user criteria outside of user criteria and so i i figured out that all these condition builders for user criteria were just strings and so i just i just did that grab them and combine them to create a query basically a before query rule to say you could only see all these things because of all these conditions so it's a neat little hack just fyi pro tip and we're doing something similar here right we're essentially taking what's current and then we're just appending to it right right okay so let's let's talk through this right so our our data filtration said if you if you have the survey reader role you can see active records right that's active is true if you have that rule what we're saying here is the like the reverse of it right if you do not have survey reader you you cannot see uh active once and active does not equal true so you're only going to get fault you're going to get inactive ones false active equals false correct now i'm going to ask this because i'm sure someone will want to know why aren't we doing active equals false so if we wanted to automate this right the reason why we don't is if we wanted to automate this we get back active is equal to true so if we think of every use case that exists like it could be you know category is equal to you know foo i don't know what the other categories are but i do know the not of what we have going to use our famous like es20 uh es12 you know replace all functionality and we just have to replace equal signs with not equal signs i like that i like that that makes a lot of sense so let's let's test this [Laughter] do we still need this here though so that is what that is doing is is kind of making it more performant we don't really need that but i want to make sure when does this run when we do a a filter that i don't let's take it away for now let's let's remove it because done it's my brain is already struggling to keep up with how many knots we're doing [Laughter] okay and so i think i was the one impersonating so let me get my quick sharing uh i think i don't need you to quit sharing um because i think i can uh take it over so who was it that i guess i'll just show both people again nice oh hey look at that nice yeah all right so let's impersonate abel and our expectation of abel who had itil is he should not see records correct and because he's the one that will lose right but he did see the security constraint so now we're going to see if he doesn't see the security constraint all right so yeah see no security constraint so you're only always false yep and he only sees that which is good and now let's check our other person to make sure that that they should still see all the records right i really should have created a better menu for that and look at that so our before business query worked crazy now how do we automate it yeah yeah yeah so uh the first thing i want us to test is i'm going to stop sharing if you want to share your i'll show through yours the first thing we want to test is remember how you saw that subject condition uh yes here yeah so take that xml what we should check if if has role you pass in that cis id does uh does that still work all right so has role the cis id that comes from that should be should be the cis id of the role correct that's what you're thinking correct so so that is that or actually i guess that goes up ahead right that looks different didn't can you copy the whole the subject role just to make sure i'm not doubting that you you i was just like i thought it had different societies i'm new to this whole copy paste thing no it's probably right you're probably right i i just there we go yeah no it's it's the same one perfect so now so you're thinking yeah line seven you're thinking if we can do that and if you can't i mean if it doesn't work that way um we could still we just have to query for it right yeah exactly you just run a query on it okay so that's that and then i'll try impersonating again give it a second let it do it yet well i still need to get back to the [Music] to the thing so just wait for you there we go and and so that didn't work because this guy got he just got troy yeah that broke that broke big time okay so no problem so we just need to then do a little a little query for it so um cool so we know what the end result is and again like we're we're even cheating a little bit here right like we're only supporting roles like groups would be a different thing so you probably would write a script include that is doing a lot of this logic um but what we'll say is for now let's just try to see if we can automate just getting the role assuming role is the is the is the solution so so the first thing we want to do is try to to query that record that that data filtration that we just did so the table of that data filtration i need to go find it as well oh you know what i should be doing i should be using something much easier oh that's nice right and thank you our nude on sn tools thank you and then and this gives you access to actually finding tables right oh no maybe not i don't i don't know about that so the data filtration records live on the cis underscore df underscore data underscore filtration you know what's going to be interesting here is like how how do you get that record and i think um this is where we would actually use flow designer right so we can even oh to build the automated piece yeah um so for now we're gonna just i would shortcode it to the that's this id uh of this one yeah but i think we if we have time we'll we'll convert this to a flow designer i guess we could do git huh yep you can just do get for this one let's do this oh well that's not gonna work yet we still gotta so now you can go pull the those those values right so the df dot um get get value right value and those are so the data condition is data underscore condition and the subject condition is subject underscore condition yes data condition and subject condition okay i'm so excited on on here that we're writing code it's you know it's it is so true this i love writing code um and you know with a change in uh my roles i don't get to write as much code as i used to and so i do miss it it's nice to get back in keep you from getting rusty yeah so so this gets a little tricky by the way if uh they didn't put anything in data condition so we're going to write a check to make sure that they put something in the data condition so i have another i'm concerned about something well maybe not maybe there's okay so table is there because in the xml and i know it doesn't show but data condition the xml element has a table in it um but table does exist as its own thing i was concerned there for a second that i was going to be something weird you'll get it exactly so as long as if dc exists and and oh you want to do and just that and it's not an empty string i know like if yes 12 was here it should be easier but um okay so if it's not so then now we have access to the data condition which is going to be our adding so then i would do like query equals well do we also need to uh do this real quick query well i just meant um we don't need to you don't think so no because like our business rule is running on the table that's if like well we will need to do the table one but we'll do that in flow designer because we'll have access to that there okay so let's just create a query variable uh yeah that's fine we could do it here um and this is going to equal dc now we're going to replace all no yeah replace all and it's going to replace all the equal signs with the not equal signs cool so then so now we've satisfied that what we're going to do on line 20 right um so that part's good so now we need to solve the line 17 one right so for line 17 so so pretty much after line 14 we're gonna have to um uh do do a query right do another query oh what is that table cis user role isn't it cis i thought oh no that's group members roll are you sure that that's that's this underscore user underscore rule cis underscore user underscore role right yeah yeah you got it okay so then hr.get oh wait first we need to extract it from our our sc variable when you do some like like splicing right because it says subject role equals and we need everything after the equal sign oh well okay so we'll just do it quick so i don't have to look up a i always do a temp equals what is it um subject condition right yeah and we're making an assumption here only one subject condition right now but again like like you would write a whole like script to handle all the edge cases here so yeah you totally would you really want to go through this and make sure you're not uh um i think and i think this is why they didn't do it in in the first right like like there's so much that they'd have to consider in order to yeah yeah for sure okay beautiful so now we boy what happened there welcome back um all right so line 19. so we're on if that does exist then what we want to do is set has role to equal gs dot oh no gs dot has roll and the roll oh we actually needed oh i got you i think it's name but i'll tell delta check yeah its name nice okay so oh i guess i don't have to it's already false to begin with yeah so now i guess inside 19 if has roll and then you just i guess if not has roll right then do the current add encoded query of the query above current oh so current dot add encoded query and then just pass it query and so in theory we just replaced what we did yes in how many lines of code does that mean wow yeah but this is again it'll actually be less than flow designer right because we can do lookup records and get data pills and things like that um so let's comment out line 26 you want to take out that whole block yeah that whole block and let's just add a little uh gs.info or or something i guess i guess if we run oh we'll run script tracer we'll run script tracer i think it'll be okay so let's uh actually now like add a gs info in there but like let's just use it okay here here's another pro tip always start your stuff with something you can find i like richie rich so what do you want me to spit out here uh query and has role and i mean a kind of a bunch of variables here just so you want has roll oops i also like to pipe separate my stuff just so i can keep an idea of what i'm throwing out there if we were in a scoped app for this one like we could do the es12 stuff where it's template literals i remember that that was so nice yeah and someone told me actually off off screen that replace all is still there so i think servicenow wrote their own replace all um oh really it's interesting uh i think that's that's pretty good we could probably do this guy here oh that's gonna be massive i think so i think it'll be huge no i think that's good i think that's good okay all right you do you want to run it i'll bring up um yeah just you can go in the background yeah i'm gonna i'm gonna grab blogs real quick we're gonna see if troy sees his records again or did we break everything yeah also possible and put a hole in the universe nope so troy sees his records again nice and and then now we'll see if abel i really should just go to this guy and he doesn't so look at that so now we have the automation pieces now let's let's see if we can in seven minutes build a flow let's do it all right do you want to build the floor you want me to build it yeah i'll try building it let's see yeah okay i hate when you're on like a a small like screen there's like a little bug with that like a ui oh your snake goes to the left it's so weird all right so so now that uh john has all the pieces on his i'm gonna try to remember it we're gonna see how this goes so pretty much on this flow we want it to trigger any time someone updates well let's assume create because we can make it support update but then you have to you have to do a little bit more as well create before query rule so while you're doing that real quick let me i'm going to share the log statement so people can see how that came through um so you can see here it's easy to find and then we can look and see what those queries come out to look like um and it's i mean you should we knew it was already going to be um that for the subject criteria and then i believe well i was dc i don't remember which order it was in but you can see that it gives you um both pieces of what we were querying for right so that's kind of neat that the logs um they show out what i expect it to be and you can see it applying uh because incident has oh that's the other thing uh they were talking about how this if you if you i think it's check mark isn't it um cascading so any of the tables cascaded off of or extended off of incident they're also going to apply and i think that's where these extra log statements come from because you can see universal caller or caller id universal request and so forth because those are cast or uh extended off i think that was because i originally went to that table and it had that pre-defined filter and then i refreshed it so i think that's why i ran a few times oh okay but the cascading but anyways yeah the cascading still does the thing yeah that's yeah uh if you show them back to my screen what i've done is data filtration is on create we're just gonna assume every time it creates for now we're gonna do a lookup record um let's not do a lookup we're just going to create a new record create a record it's been a while since i've been here oh my gosh uh create record all right what happens when you get out of the game for a minute all right so the table uh needs to be the from the data filtration record oh your instance is slow wow okay i said yeah we have table name so we should drag that there so now we got the table um oh actually oops i meant the table here is business rule business rule because we're creating a business rule going going crazy here so we want the uh query to be checked you want the name to be the description of this um you know what maybe we'll leave it um well if you're making a description we'll put it like we'll put the sis id of this right something like that we'll just put some relevant information yeah but i think if you wanted to add text to it though you'd end up having to do like a script on that yeah data filtration oh can you just do that oh that's nice sis id and then we're going to do subject name or subject condition just so we have this kind of stuff to compare and then we want the data condition yeah cool okay so what else was your business rule i think that was the only thing checked it's by default it's gonna do a before um and then we just went to advanced yeah cool so script so here is where we would you know write write a little bit of that script so essentially we just need it to return that code that you just did uh you want to select it yes i will yeah because i think i'm gonna need to do i'm gonna click done for a second so before we do that i need to go and and look up some records right so we're going to look up some records the table is going to be on incident because or actually the table is going to be cis user role do you remember we had to look up the user role right and that's going to be where cis id is equal to oh and then we have to do the split yes so let's pull some of your code okay so something like so the split is fd data dot trigger dot current subject condition so we take that subject condition we split it we have this and now we're gonna return [Music] that's a u not an i i just that's all we needed right so oh no i need to do cis id equals plus okay so i think that we're good okay so we got the user rule what else did we need to get um and then we needed to do a replace all on the data condition so this is where i think we could create like a flow variable for that um let's save this for a second before i break stuff okay um so in this script we now have access to the role so that could be something like or actually i'm trying to to think what how best to do this oh it's getting complex um so we need to return like a string of this all right so maybe we'll we'll stop it we're getting close to like um so essentially what we need to do is probably a a gr record here again but now that we [Music] we are [Music] essentially what we're trying to build is on the business rule we're we're trying to build this as a string right so it'll be some sort of and this is where that like es12 literals would come in because that would be nice but like we're trying to build you know some sort of you know string that we could oh the query well we need to return like like it needs to look you know pretty much like this right um because the business like because we're creating this entire record right so this entire record needs to to kind of like return at least this part right so the so the record so in the in the flow designer we need to say we need to set uh has roll right equals to gs dot has roll of the roll name that we just did and then we also need to just do this this part of it as well so maybe that is maybe i'm thinking this is too too much um so [Music] [Music] so is this going to run a uh eval on it no no it's not and we don't want it to oh we just want to put this oh because we're just we're just setting a value to the field i gotcha i see what you're saying fd so that returns the name and now we're closing those friends so yeah so that's has roll [Music] um so then the next one was our uh if you love my naming conventions if has roll and oh if not has roll if not has rule then i can actually just do it this way wow that's going to be nice current dot add encoded query and then this is going to be the data condition oh not that one it's on the trigger oh no [Laughter] sometimes like it's i don't know if it's slow or because you know sometimes this editor doesn't work as as well so current dot data condition plus this that so yeah i think that's and then i just need to return wait i think the only yeah so i think that's i think we're good so return ff plus fff all right do you need i guess the semicolons are fine they're they'll prevent it no no i'm i was just thinking about new lines or something like that because it will process it as a straight single single string it won't the this the semicolons will prevent that okay but normally yeah i could put like a new line there or something but um all right so i think that was it like so if you're gonna test it yeah if you want to test it though turn off the the other business rule right or or i guess it'll create a new one won't it yes it will so well though i think your trigger though is going to be a problem you'd have to create a whole new no i think we're good so well it's trigger on creation though of the data filtration rule it'll just pretend you did it as a creation oh right right right yeah the testy knife i always forget about that part so wow your instance is super slow all right so we'll see if all that code you wrote we simplified to do this let's see okay so we looked up the record um survey reader right we got it so that looks that looks right so far um we created a business rule and we this is the record so look has role survey reader if not has role current ad encoded active equals oh i forgot to do the replace all oh but that's that's pretty good though that i mean that was pretty good yeah look at that wow let's see if that i just want to delete it so because it's going to create a name with the same one okay right now and thank you logs for this so i think all i need to do is let's take this guy uh just to be good about it for rfe string or replace equals fe dot replace all or actually yeah i mean we'll try that and see if that works not equals and then fe and i can do like a two string or something like that if we need [Music] but all right so let's save that since our test went so fast oh instances liking me today all right we go into here we look at this not nice all right so now the question is so note this one's inactive if i refresh this we have our our business rule oh oh i forgot to set the table that's that's running global oh no spread it on everything all right let's while that's loading because that's gonna take a while um did it not wow come on john you could have seen that i missed the table here yeah probably that's okay so now we're running it on incident save that cool let's delete this oh i also saw that i needed to to put this in a string [Music] okay i'm feeling good nice all right and then that's going to run and we're just going to see if that actually worked and if that did this is an example of like now you have the framework to you know build as many of these as you wanted right so oh this is missing that one oops i gotta do that one more time sorry sorry doing things in scripts you gotta like remember to to to keep your parents correct so i'm just going to save i'm just going to change this manually because that'll work because the other one worked okay and now we're going to impersonate somebody if that worked nice after this record saves because your instance is so slow i think the only downside of that or actually no i think it's good because it'll capture it in your update set because you're creating it flow's going to run so like like that that would be workable and you can add more checks right to make sure that you know a certain criteria is only certain things um so so all incidents so this person only sees 28 no no security issue and no whammies big money bam yeah and i like it i was trying i was we're running out of time and i'm like 15 minutes but it's okay nice we did it we did it and i feel good like i think i think we we came out we i mean we talked a lot in the beginning but like i think we we talked over data filtration we even did like you know the exploration of how we would build the automation because we did it manually yeah and then and then we we even showed flow designer where how like simple it is to do a flow designer if you kind of know the logic you're you're looking for yeah no i and and i guess if flow designers out of your wheelhouse you can just you know run a a business rule on the table so as they get created it would create the before business query um to solve that issue but again this may all be for naught if they release it and allow you to set it as a before anyways then you won't have that problem but it is neat to see that there are solutions available until that happens right yeah i could totally see like someone coming out with a package for this or an update set where you know it's just a bunch of flows that handle all the use cases i mean we only handled a very small sliver but i think like right you know there's definitely lots of uh possibilities here so yeah no i agree well this has been a fun one getting into some code into some admin stuff yeah and it worked and it totally worked wait are you what are you trying to say i just said like i didn't know if that was gonna work so yeah no that's good though yeah this has been a good one all right well we're at our out well we're over our hour but yeah we'll see you next time people [Music]

View original source

https://www.youtube.com/watch?v=HJsu7Fu8KlU