Security on attachments

Hello, I’m trying to give a role access to add/edit attachments to operations on routes without giving them full access to the ProdRoute table. I tried using Extensible Data Securities but can’t seem to get that working. Is anyone able to help me?

This is the form I"m talking about. The role in question will have the New and Delete buttons greyed out but I want them to be able to click the attachments button on the bottom and add a note.

Have you tried by setting “Always enabled” on Active document tables. (Organization administration → setup → Document management)?

I can’t seem to get this to work, but even if I could, my worry would be that this will allow any user with read access to that form be able to edit notes. I would prefer to restrict this ability to a particular role.