Change Notices Can Promote Read Only Objects???
Changes Notices (CN) do not respect a user's access defined in the Access Control Lists (ACL's). Read only objects can be added to the CN Resulting Objects with a Target State. Then the CN workflow runs as wcadmin so it has no problem promoting everything (including read only objects). Promotion Requests give desired error of 'Insufficient Permission for promoting an object in this context' to users on read only objects when they try to submit but Change Notices do not.
I created a ticket with PTC, but R&D said that CN's should not respect user access because the people reviewing/approving the CN should be doing it. R&D also said CN workflow can be customized using expression robots if we wish to check permissions. My thoughts: having approvers check is easier said than done when there are hundreds or thousands of Resulting Objects in a CN, and I'm not super excited about customizing/maintaining a custom CN workflow.
The net result is we keep having users accidentally change the state of read only Library objects from Released to Obsolete once or twice a month. Also, our Creo drawing formats (.frm) get set to Obsolete from users forgetting to remove them from the CN Resulting Objects list since there is no way to auto exclude drawing formats from common actions/collectors.
How have others dealt with this? Seems like a major gap in permissions for CNs.

