Skip to main content
Brayden
Gainsight Employee ⭐️
Gainsight Employee ⭐️
February 20, 2024
New Idea

Please add ability to restrict Company Persons in Customer Cheat Sheet email share

  • February 20, 2024
  • 27 replies
  • 499 views

Hi Team, 

When sharing Customer Cheat Sheet from C360 by email, the search bar includes Company Persons, which could possibly be a risk since there may not be information you would like to share with your customer in the Cheat Sheet. 

It would be very useful to have the ability to restrict this search list to just Internal Users to ensure this information is not shared erroneously with a customer contact. 

Thank you. 

27 replies

darkknight
Expert ⭐️
February 29, 2024

Thanks for the update @AshutoshSingh  but I respectfully disagree that this strikes a balance between flexibility and security, and your justification (quoted below) doesn’t make sense to me as it relates to the issue raised.
 


The current behavior i.e allowing the sharing of raw Cheat Sheets externally was primarily driven by the need for flexibility within organizations, cases where users do not have Gainsight licenses but need to get a quick overview of the state of their customers will be benefited from this.
 


How does sharing Cheat Sheet to PERSONS externally relate to the need for USERS internally to gain a quick overview of the customer?  

Sharing with USERS internally is not an issue, and should address the case you cited above. Sharing with PERSONS externally IS an issue - it’s a security hole.  You’ve given us no guardrails to ensure a user doesn’t inadvertently send private data externally. 

Admins absolutely must have the ability to restrict users from sharing Cheat Sheet (or any Gainsight data point) with PERSONS/CONTACTS unless/until the business understands how/when to use and accepts the potential risk.  

Having the flexibility to enable or disable the ability to share with EXTERNAL PERSONS would be striking a balance.  Not what you’ve suggested.
 

Jeff Kirkpatrick
darkknight
Expert ⭐️
February 29, 2024

@AshutoshSingh I’ll also note that the documentation does not at all state anywhere that I can find this is an intended use case for Customer Cheat Sheet. It is all geared toward using CCS internally amongst USERS (particular Execs) - not PERSONS.

So again, I respectfully disagree with Gainsight’s stance here. I was a CSM in a previous life, and I would have never shared CCS externally. 

Jeff Kirkpatrick
darkknight
Expert ⭐️
February 29, 2024

intenti

 

 I was a CSM in a previous life, and I would have never shared CCS externally. 

...intentionally.

Jeff Kirkpatrick
mobrien14
Helper ⭐️
February 29, 2024

@AshutoshSingh While I definitely see the value in those features, they don’t really address the concerns of organizations who do not want the external sharing enabled at all. We can remind CSMs & leaders not to do so, but there’s no real way for us to prevent them and it could easily happen by accident if someone isn’t paying close attention.

We really need just a simple on/off toggle in the Horizon AI settings for admins to disable this org-wide. That’s the only way I/we can roll this out with confidence that clients will not see internal notes. 

dayn.johnson
VIP ⭐️⭐️⭐️⭐️⭐️
February 29, 2024

@AshutoshSingh While I definitely see the value in those features, they don’t really address the concerns of organizations who do not want the external sharing enabled at all. We can remind CSMs & leaders not to do so, but there’s no real way for us to prevent them and it could easily happen by accident if someone isn’t paying close attention.

We really need just a simple on/off toggle in the Horizon AI settings for admins to disable this org-wide. That’s the only way I/we can roll this out with confidence that clients will not see internal notes. 

☝

THIS.

There should never be a situation where clients need to see internal notes.

Staff CS Content & Comms Manager, 2x Gainsight CS Ops Product Council Member
bradley
Expert ⭐️
February 29, 2024

While the proposed mitigations are helpful if an org decides to allow external sharing, none of those solutions address the concern expressed by the community which is “allow us to disable external sharing for this feature”.

iainr
Contributor ⭐️⭐️⭐️⭐️
March 18, 2024

Having just had approval to start testing Cheat Sheet internally I’ve run across this issue and we’re now very likely to prevent the rollout of the feature to our users until a solution is provided to disable external sharing of cheat sheets externally entirely. Which is a great shame, as the feature is very promising. Please address these concerns asap Gainsight team!

darkknight
Expert ⭐️
March 19, 2024

@AshutoshSingh as you can see, there are others that still consider this a blocker to roll out Cheat Sheet.

Please acknowledge.

Jeff Kirkpatrick
Contributor ⭐️⭐️⭐️⭐️
March 19, 2024

Adding that I am facing the same challenge and has made us hesitant and unlikely to roll this out until we can disable sharing to company person.

darkknight
Expert ⭐️
April 24, 2024

@AshutoshSingh  My CS leadership team really wants to use this feature, but agrees the risk is too great to put this in the hands of CSMs, especially considering that the UI for sharing Cheat Sheet and the UI for Email Assist look nearly identical (see below). It blurs the lines between what should and shouldn’t be shared externally. 

For end users, often the reasoning is if something is “possible” then it must be ok to do. You have to give admins the ability to keep them from shooting themselves in the foot.
 

From the way Cheat Sheet has been marketed and documented, it was designed to be an internal tool, not an external one.  Rather than implement granular access controls, which I understand will take a lot of time to work out, can you not just disable the ability to share externally? I have to believe the use cases to share internally far exceed the use cases to share externally - (I can’t imagine why any company would want to share this info externally.)

 

 

Jeff Kirkpatrick