Finlay.worksBareBones Ticketing manual

Departments And Access

A department is the unit that owns tickets and work. People reach a department through a group. This page covers creating departments and mapping groups to them.

Before you start

  • You need SystemAdmin and a satisfied step-up. Every workspace on this page is whole-page gated. See Admin Settings and step-up.
  • The groups you intend to map must already exist and be active. See Users and groups.

Access levels

Access is granted to a group, not to a person, at one of three levels.

Level What it permits
View Read the department's work.
Work Everything View permits, plus ordinary ticket work in the department.
Admin Everything Work permits, plus elevated operations inside the department.

The levels are cumulative: Admin includes Work, and Work includes View.

Department Admin is department-scoped. It carries no product configuration authority and is not SystemAdmin.

Effective access

A person can belong to several groups mapped to the same department at different levels. The highest active mapped level wins. A person in one group mapped at View and another mapped at Work has Work.

Only active mappings count. Disabling a mapping, disabling the group, or disabling the department removes that path from the calculation.

A department mapping grants department access only. It does not grant project authority, approval authority, or SystemAdmin.

Create a department

  1. Open Admin Settings and complete step-up.
  2. Open Department Administration.
  3. Review Department roster. Use Search departments and Status filter to check the department does not already exist.
  4. Select Add department.
  5. Enter a Department name and a Department key. Use a stable operational team name, not a project name. The key must be unique, and must be 2 to 12 characters using letters, numbers, or underscores.
  6. Select Save department once.
  7. Open the department detail page and confirm the name, key, and enabled state.

A paused department stays visible and reviewable but does not accept work. It cannot receive an active access mapping. Before re-enabling one, check what routes to it.

Map a group to a department

  1. Open Department access administration and choose the department.
  2. Select Manual access, then Add manual access.
  3. Choose an active group.
  4. Choose the lowest level that lets the group do its job: View, Work, or Admin.
  5. Save once.
  6. Confirm the mapping appears as active in the department's mapping list.

An inactive group or a disabled department cannot receive an active mapping. The save is refused.

Remove or restore a mapping

  1. Open Department access administration and choose the department.
  2. Locate the mapping.
  3. Select Disable mapping. The group loses this access path. The mapping stays visible as history.
  4. To bring it back, re-check the group and the level, then select Restore mapping.

Disabling a mapping does not delete it and does not change group membership.

Apply access automation

Automation derives mappings from group or directory attributes instead of listing them by hand. Manual mappings remain as deliberate exceptions.

  1. Open Department access administration and choose the department.
  2. Open the Automation tab and review its defaults, then the Rules tab.
  3. Add a rule only where a real group or directory attribute should decide access.
  4. Open the Preview and apply tab.
  5. Choose the preview source: the stored snapshot, or a live directory read. Changing the source discards the previous preview.
  6. Review the proposed access, the winning rule for each person, the warnings, the people affected, and the worker impact.
  7. Select apply once. BareBones Ticketing re-checks your grant, your step-up, the automation state, and licensed worker capacity before writing anything.
  8. Confirm the applied mappings and the run history match the preview.

A preview is not a change. Nothing is applied until you apply it.

Revert acts on one earlier automation run. Preview and review it before reverting, the same as an apply.

Automation is SystemAdmin-only. Department Admin cannot configure or run it.

If it does not work

  • The save is refused because the group is inactive. Reactivate the group through Group Administration first. Do not map a different group as a substitute.
  • The department key is rejected. There are three causes. The key is blank; it does not meet the format rule — 2 to 12 characters, using letters, numbers, or underscores; or another department already uses it. Search the roster, including disabled departments, before changing the key you wanted.
  • Apply is refused on worker capacity. The change would put more people over the licensed worker limit. See Limits and scope.
  • Apply reports an error and you cannot tell what changed. Re-open the mapping list and the run history before you try again. Do not repeat the apply blind.