Documentation / Operations
Users & access
Roles, scoping and audit — including the rule that a narrowed user who cannot be scoped sees nothing.
Roles
| Role | Sees |
|---|---|
| Owner | Everything, including commercial and licensing |
| Analyst | Operational surfaces across their assigned clients |
| Finance | Commercial surfaces; no client estate detail |
| Dispatcher | Scheduling, capacity and the queue |
| Client contact | Their own organisation, through the portal only |
Scoping fails closed
A user narrowed to specific clients sees only those clients. If the scope cannot be established, they see nothing — never everything.
This is enforced at the database, not in the application. Row-level security applies to every query on every table that carries a tenant.
What is withheld and why
Some surfaces cannot be attributed to a client at all — the audit log has no client column by design. Those sections render withheld for a narrowed user, with the reason.
Withheld is a third answer, distinct from empty and unreachable. Withheld counts are null, never zero.
Break-glass
A break-glass account exists, is excluded from automation by construction, and every use is recorded and surfaced. It is never a route around an approval.
What is never collected
No productivity measurement, no inter-technician comparison, no behaviour profiling. A preference scoped to a technician records a working convention, never an assessment of a person.
Not running it yet? Start a thirty-day evaluation — read-only, on your own estate, no card.
Thirty days · read-only · no card
Run it beside what you already have, against your real clients. It tells you what your tools are reporting that is not true.