Tracker security: Profile widget still exposes TEI attributes when using Attribute Category Combo for NGO data isolation

Hello DHIS2 team,

I would like to ask whether the following behaviour is expected by design or whether it is a current limitation of Tracker security.

Environment

  • DHIS2 Capture (Tracker)(2.41)
  • One Tracker Program
  • Multiple implementing partners (NGOs)
  • All NGOs work within the same Organisation Unit.
  • The program uses a Category Combination with Data Dimension Type = Attribute.

The category is:

Implementing Partner

Category Options:

  • NGO 1
  • NGO 2
  • NGO 3

Each Category Option has its own sharing settings so that each NGO only has Capture/View Data permission for its own Category Option.

What works

The configuration behaves exactly as expected regarding data isolation.

Each NGO can only:

  • view its own events,
  • create its own events,
  • modify its own events.

Events belonging to another NGO are completely hidden.

This confirms that the Attribute Category Combo successfully isolates Event data.

Remaining issue

The problem concerns the Profile widget.

If a tracked entity has:

  • one enrollment/events belonging to NGO 1
  • another enrollment/events belonging to NGO 2

then:

  • NGO 1 users still see the complete TEI profile (Tracked Entity Attributes).
  • NGO 2 users also see the same TEI profile.

Only the Events are filtered.

The Profile widget still exposes all TEI attributes, even though the user has no access to the other NGO’s enrollment/events.

Expected behaviour

From a confidentiality perspective, we expected that a user from NGO 1 would not be able to view the TEI profile if the visible data belong only to another NGO.

Ideally, when using Attribute Category Combos for partner-based data isolation, we would expect one of the following:

  1. the Profile widget to respect Attribute Option Combo permissions,

or

  1. a configuration option allowing the Profile widget to hide TEI information when the user does not have access to the corresponding Attribute Option Combo.

Question

Is this behaviour expected by design?

Is there any recommended configuration that allows complete TEI isolation between implementing partners working within the same Organisation Unit?

If not, would this be considered a limitation or a feature request?

Why this is important

This scenario is particularly relevant for community-based health programs where multiple NGOs work within the same health district while patient confidentiality must be preserved between implementing partners.

Thank you very much for your guidance.

Hi

Thank you for the detailed topic with the helpful explanation. I believe it’s exactly similar to the issue you are facing here: Capture app – Profile widget displays TEA values despite Sharing permissions and Program Rules – can I merge these two topics of yours into one please?

It’s currently being discussed by the team. We will get back to you when a ticket/decision is created/agreed upon.

Thank you! :folded_hands: