Mask PIN entry on SFM

We have an SFM which allows the user to digitally sign a Work Order by entering the Salesforce ID PIN on the screen.  The PIN is unmasked and is displayed on the screen until the user saves the SFM.  We would like the PIN to be masked with asterisks upon entry.  This is a compliance issue for us in the medical device arena.  The requirement is needed for SFMs run in the browser and also the ServiceMax iPad app.

What is the underlying problem do you intend to solve with this idea?
We need to solve a compliance issue to provide privacy and security for PIN entry on an SFM.
How is the problem being addressed today, if at all?
It is not being addressed, as we have yet to find a technical solution for the problem.
Product Area?
Work Order Management Other
What version of ServiceMax are you on?
Summer 16
7 Comments
Customer Success Team
Customer Success Team

@susanbmichel Does this still happen in your current version?

 

@shivaranjini_g   Could we please get a status on this one?  Thanks!

Product Team
Product Team
Status changed to: Under Consideration
 
Customer Success Team
Customer Success Team

@shivaranjini_g   Thanks for the status update!  

Pastry Chef
Pastry Chef

Hello @susanbmichel. I'm not sure which Salesforce ID you are using, but if you are using the Engineer's Salesforce ID as a PIN on the Work Order then this might work for you.

What if in an SFM you only asked the Engineer to add their name to a lookup. Then via Lookup Form-fill, you could fill in the ID into the PIN field in the background. Neither the Engineer nor customer would see the actual PIN.

I would be interested in understanding your use case better.

Sushi Chef
Sushi Chef

@mmajerus6 Thank you for the response.

We use the PIN feature on the Salesforce ID. The user sets this PIN and is the only person who knows the value. (See screenshot) It appears this is a ServiceMax feature, now that I look at it.

We use the PIN as a signature. This is our flow:

> Dispatch work order to technician. Store the technician's salesforce User ID on the work order

> Process the work order fully to Completed status.

> Open an SFM called Sign and Close WO. Two things appear on this SFM:

1. salesforce user ID box (defaulted to null)

2. PIN box (defaulted to null)

> Field service engineer has to type his full Salesforce user ID and PIN. Together this is an authentication that serves as a signature. It is an important step in our quality process. The FSE needs to enter in the PIN, rather than have it defaulted.

> ServiceMax first confirms the Salesforce ID was entered correctly.

> Then in the sync, we confirm the PIN was correct

> Work Order is closed

The issue is that when the user is on the SFM and types the PIN, it is not masked as they type. This is poor security as anyone could view that information over the FSE's shoulder. We would like the option to mask the entry of the PIN (or any field) on the SFM.

I am happy to walk through a demo if that would help clarify.

Susan Michel

Snap45.jpg

 

 

 

Customer Success Team
Customer Success Team

@shivaranjini_g  Please let me know if you'd like for me to set up some time for you to see this.  I can coordinate with @susanbmichel 

Product Team
Product Team

Thanks@lisa_mercer

From the flow that @susanbmichel has detailed it is clear that the ask is to mask the value as user types into the field, similar to password fields.

@susanbmichel the screenshot is of salesforce UI. Is it 'Encrypted text' data type field. Even then the encryption happens only on saving the record. This is not supported on our product yet.

We are working encrypting field values such that, only those with valid permission can view content on the record.

Regarding the ask on masking any SFM field values as user types, will further review and update this thread.