Skip to Main Content
Vellox Group Ideas Portal
Created by Leigh Morkel
Created on Sep 2, 2026

Restrict Forum Post Editing to Original Authors and Enforce Comment Integrity

1. Problem Statement

In the OSS Safety Report module, the Forum / Discussion section allows users and stakeholders to collaborate, ask clarifying questions, and document findings during the investigation process.

Currently, the forum permissions allow any user with access to the report to edit or overwrite existing questions and comments created by other participants.

This presents several significant operational and compliance risks:

  • Integrity & Deception Risks: Instances have occurred where an original question or critical comment was completely erased and replaced with altered text by another user, distorting the context of the inquiry.

  • Audit & Accountability Challenges: Although modifications are logged in the backend Change History, having live text altered on the active forum creates confusion, misrepresents the author's intent, and compromises data integrity for safety investigations.


2. Proposed Enhancement & Functional Requirements

Enhance the Forum / Comments functionality across Safety Reports (and related modules) with strict author-based permissions and integrity controls:

  1. Author-Only Edit Restrictions:

    • Restrict editing permissions for any forum topic, question, or comment exclusively to the Original Author / Requestor.

    • Standard participants should only be allowed to reply or add new comments, not modify existing entries submitted by others.

  2. Configurable Edit Window / Immutability Options:

    • Provide a global/module setting under Safety Options > Global Settings:

      • Option: Immutable Posts: Once posted, comments cannot be edited by anyone (replies/addendums only).

  3. Visual Revision & "Edited" Indicators:

    • Include a direct inline "View Revision History" link showing the diff between the original submission and the edited version. Similar to the Findings/Actions tab.

  4. Role-Based Admin Override:

    • Only designated roles (e.g., Report Manager, System Administrator) should have moderation rights to hide, delete, or redact inappropriate content, with mandatory reason logging in the Change History.

  • Attach files