Written by DROPS.ST.
Decide delivery-data access from the task. Preparing items, coordinating handover and resolving a delivery problem need different information. An address should not become general staff information merely because it appears on an order.
DROPS connects customer and item context with orders, with separate controls for order responsibilities. Use that foundation to review which orders staff need and how information leaves the screen. Verify the actual view rather than assuming a role name hides individual fields.
The permitted delivery model and required customer checks need separate confirmation.
Map the need before assigning access
Name the task, necessary information and point at which that need ends. This is a proposed business matrix, not a claim of independent field masking in DROPS.
| Task | Information to justify | Information to question |
|---|---|---|
| Prepare items | Order reference, items and quantities | Full address or unrelated history |
| Coordinate handover | Destination, timing and necessary contact | Unrelated personal details |
| Perform assigned delivery | Destination and approved instructions | Orders outside the task |
| Resolve an exception | Relevant order facts and contact | Unrelated orders or speculative notes |
| Reconcile a charge | Transaction and supporting evidence | Full address unless genuinely needed |
| Update catalogue copy | Product information | Customer delivery details |
Where roles combine tasks, review the combined need explicitly.
Distinguish record access from field access
The DROPS order view includes delivery information when present. Order permissions or assignment can authorize viewing; that does not establish per-field masking or location isolation.
Test whether the worker sees more than the task matrix requires. If the intended restriction is finer than the demonstrated view, agree a controlled handoff or verify a supported solution before granting broader access.
A missing menu link is not an access boundary. Authorization must hold when the record or action is requested. OWASP authorization guidance.
Use the staff permissions checklist to examine wider powers. Catalogue editing also permits customer-account edits and wallet adjustments; it is not delivery-only access.
Review copies and external handoffs
Include downloads, printouts, copied instructions and dispatch tools. Restricting the main view does not retrieve existing copies. Ask who can create them, what they contain, who receives them and how they are handled afterward.
Individual order downloads follow order-view authorization, so inspect those actions together. OPC guidance recommends need-to-know employee access; the task matrix helps examine that need without proving legal compliance for a configuration. OPC safeguards guidance.
Hypothetical example: packing and dispatch
A preparation worker and dispatch coordinator both need the order reference, but only the latter task needs the destination and contact instructions.
The owner tests the preparation worker’s view. If it exposes the full delivery record, a packing label does not establish a field restriction. The team must choose a supported view or controlled handoff matching the intended policy.
The coordinator checks the current order address rather than an old copied message. This hypothetical workflow does not establish a native driver app or automatic address mask.
Test both sides of the boundary
Use synthetic addresses and disposable orders, with agreed expected results:
- Open an authorized order and inspect its fields.
- Request an order outside the intended responsibility.
- Check relevant status- and assignment-based access.
- Test direct links, downloads and print actions.
- Change test access through the approved procedure and recheck.
- Confirm remaining authorized staff can still perform the task.
Record the implementation’s actual behavior. A failed restriction remains unresolved; renaming the role does not fix it.
Assign exceptions and cleanup responsibility
Name who verifies an address correction, updates the record and communicates instructions. Use the approved process rather than scattering personal details through a general group chat.
Review copied material and delivery access when duties change or someone leaves. The employee offboarding checklist covers that handover.
DROPS gives the team connected order context. Pair it with task-specific decisions and proven view boundaries so staff can complete the handover without distributing every detail to everyone.
Explore DROPS.ST and the shop demos. Bring the matrix and two synthetic orders: one the worker should handle and one they should not access.