The goal is to allow anyone to view a resolved ticket (issuetype SDSK) but only administrators can add a comment or change it, etc.
I have a role Administrators, who can do anything.
I have a role Read Only, who only have the Browse Project permission.
I created an issue level security with those two Roles.
On the final transition to resolved, I added a post function that applies that Issue Security (if the user is a Service Desk Collaborator, which is everyone).
I can see the ticket has the Issue Security applied, but Carol, who is not an Administrator, can still comment on the ticket.
What am I doing wrong? (Thanks in advance.)