Only the relevant user and the boss should see and process vacation requests, time sheets, etc. Administratively, it would be very helpful if there was a feature showing who is currently logged on to the client. The rule would then be to read the document, for example: vacationer = currentUser Instead of setting a separate rule for each employee, only one rule per user group would then have to be created.