User based query

In my opinion find a system BAQ used in a tracker that provides this functionality, copy it, and then customize it to your process. The target BAQ should have the built-in security. Also, you can review my post in the referenced help case:

Mazin