Documentation  /  Operations

Users & access

Roles, scoping and audit — including the rule that a narrowed user who cannot be scoped sees nothing.

CLIENTSTICKETSBILLINGSETTINGS Owner fullfullfullfull Technician scopedscopednonenone Billing scopednonefullnone Read-only scopedscopednonenone WHEN SCOPE CANNOT BE READ most systems show everything here show nothing, and say why scoping fails closed · an unreadable scope is not an empty filter

Roles

RoleSees
OwnerEverything, including commercial and licensing
AnalystOperational surfaces across their assigned clients
FinanceCommercial surfaces; no client estate detail
DispatcherScheduling, capacity and the queue
Client contactTheir own organisation, through the portal only

Scoping fails closed

A user narrowed to specific clients sees only those clients. If the scope cannot be established, they see nothing — never everything.

This is enforced at the database, not in the application. Row-level security applies to every query on every table that carries a tenant.

What is withheld and why

Some surfaces cannot be attributed to a client at all — the audit log has no client column by design. Those sections render withheld for a narrowed user, with the reason.

Withheld is a third answer, distinct from empty and unreachable. Withheld counts are null, never zero.

Break-glass

A break-glass account exists, is excluded from automation by construction, and every use is recorded and surfaced. It is never a route around an approval.

What is never collected

No productivity measurement, no inter-technician comparison, no behaviour profiling. A preference scoped to a technician records a working convention, never an assessment of a person.

← Backup & restore  ·  When inference is slow →

Not running it yet? Start a thirty-day evaluation — read-only, on your own estate, no card.

Thirty days · read-only · no card

Run it beside what you already have, against your real clients. It tells you what your tools are reporting that is not true.

Start an evaluation