web
You’re offline. This is a read only version of the page.
close
Skip to main content

Notifications

Announcements

Community site session details

Community site session details

Session Id :
Power Platform Community / Forums / Copilot Studio / Restrict sales user fo...
Copilot Studio
Unanswered

Restrict sales user form accessing records which is not shared or assigned to user

(0) ShareShare
ReportReport
Posted on by 2

I have created a PVA chat bot. In that we are calling an action and action is referring an order entity. In that entity sales user is not  having access to all the order records but when sales user is trying to access the records through PVA then sales user can see other records also which is not assigned or shared with sales user.

How we can restrict the access to sales user so that they cant see the other's record while chatting in PVA?

I have the same question (0)
  • Expiscornovus Profile Picture
    33,402 Most Valuable Professional on at

    Hi @vpathak,

     

    One approach could be to impersonate the user in your request.

     

    You could use the Microsoft Dataverse Web API with an HTTP request action and use the CallerObjectID with the Azure Active Directory (AAD) object id of the user interacting with the PVA chat bot.

     

    Here is an example in the Microsoft Docs about user impersonation:

    Impersonate another user using the Web API (Microsoft Dataverse) - Power Apps | Microsoft Docs

     

    Below is a screenshot of such a query in Power Automate. 

     

    callerobjectid_userimpersonation.png

     

  • vpathak Profile Picture
    2 on at

    Thanks for your reply.

    Could you please let us know how I can pass callerobjectid for different such user who has record based access to entity..

  • Expiscornovus Profile Picture
    33,402 Most Valuable Professional on at

    Hi @vpathak,

     

    1. Make sure you enable authentication for your Power Virtual Agent.

     

    pvabotauth.png

     

    2. Create a flow with a When Power Virtual Agents calls a flow trigger action. Add a text UserID input field to that action.

     

    userid_input.png

     

    3. Use a HTTP action like I showed in my earlier post. Use the UserID field for the CallerObjectId in the Header section.

     

    userid_object.png

    4. In your Topic setup make sure you map the Bot.UserId to the flow with the UserId field

     

    botuserid_listmyrecords.png

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Forum hierarchy changes are complete!

In our never-ending quest to improve we are simplifying the forum hierarchy…

Ajay Kumar Gannamaneni – Community Spotlight

We are honored to recognize Ajay Kumar Gannamaneni as our Community Spotlight for December…

Leaderboard > Copilot Studio

#1
Valantis Profile Picture

Valantis 325

#2
Romain The Low-Code Bearded Bear Profile Picture

Romain The Low-Code... 176 Super User 2025 Season 2

#3
chiaraalina Profile Picture

chiaraalina 119

Last 30 days Overall leaderboard