Finlay.worksBareBones Ticketing manual

Roles and Access Matrix

Find the person, find what they can do. Access in BareBones Ticketing does not come from one setting. It comes from several separate ones, and the product checks each on its own. Holding one does not imply another.

Roles and access explains this in prose. This page is the lookup table.

Department access levels

Most everyday access comes from these three levels, given per department.

Level What it lets you do in that department What it does not let you do
View Read the department's tickets, queues, and projects. Change anything.
Work Everything in View, plus ordinary ticket work: comments, status changes, assigning tickets. Change the department's settings. Reach tickets in other departments.
Admin Everything in Work, plus the extra department duties listed below. 1 System-wide administration, or anything in another department.

The levels build on each other, and each one applies only to the department it was given for. Admin in Sales gives you nothing in Facilities.

You are not given a level directly. You are put in a group, and the group is given a level in a department. If several groups give you a level in the same department, the highest one applies. 2

Everything else that grants access

Who or what What it lets them do What it does not let them do
Anyone not signed in Sign in. Accept an invitation as an external participant. Run first-time setup, but only while no administrator account exists yet. See any ticket, queue, or setting.
Someone named on a ticket See that one ticket, if they raised it, were copied in, or were added as a watcher or participant. Work on it as an agent, see internal comments, or see anything else.
A Customer Area visitor Use the customer service catalogue, see their own tickets, follow up on them, and return to the Customer Area. Their access lasts at most eight hours. 3 Use Quick Ticket, search, preferences, approvals, projects, agent screens, or any administration screen.
A System Administrator Administer the whole installation: settings, users, groups, departments, catalogue, workflows, mail, licensing, import, audit, and diagnostics. They also get Admin in every enabled department and access to every project. Automatically work tickets, act as a requester, or decide approvals. Those are checked separately.
A named project manager Look after the content of that one project. Reach the department, see its tickets, or touch any other project.
Someone staffed in a project role Be seen as filling that role, and see the project. Run the project, edit routing rules, or open its tickets.
Someone linking a ticket to a project Attach the ticket, if they have Work or better in the ticket's department and can already see both projects. Assign anyone, staff the project, change routing rules, or reveal a project they cannot see.
A named approver Decide the one approval they were asked for. Where the step is set up as regulated, that decision is the regulated approval and carries the electronic signature. Open the queue or make the status change themselves.
A named second approver for a reveal Approve one specific request to reveal redacted information. This can be a department manager of record, who does not need to be an administrator. Browse the redaction list, open the ticket, or undo any redaction.
An external participant Add public comments and see files marked safe for external viewing, on the tickets they were linked to. Sign in as a staff member, use the requester portal, the queue, search, projects, or administration.
Operator, Auditor, Import Operator, Evaluator Nothing. These are job labels this manual uses to say which instructions apply to you. Anything. They are not settings in the product.

Things people confuse with each other

Each row gives only what is in its middle column.

This Means Does not mean
You can see a project You can find it and read it. You can open its tickets, staff it, or change its rules.
You can run a project You can do the project management tasks the product provides. You have access to a department or its tickets.
Someone is staffed in a project role One named person fills one slot on one project. A routing rule exists, or that person can open tickets.
A project-role routing rule exists Tickets matching it get an owner, watcher, or participant. Anyone is actually staffed, or has access.
A ticket is linked to a project The two records are related. The ticket has been reassigned.
A routing rule ran The product evaluated it at creation, at a status change, or in a bulk run. It fixed missing staffing, or made a change the person was not already allowed to make.

Things that check you rather than permit you

Mechanism What it actually does
Step-up Asks an administrator to confirm their identity again before a sensitive change. It confirms who you are. It does not decide what you may do.
The product-use check Blocks changes when the licence is not in order. It never permits a change.
A group name arriving from your company's sign-in system Feeds into the mapping that grants access. It is not access on its own.
A menu item, notification, label, or web address you can reach Presentation only. It adds nothing.
Queue counts, filters, saved views, and the 250-row list Ways of arranging records you can already see. They never show you a record you cannot.

If you sign in with a local or company directory password, step-up asks for that password again. If you sign in through single sign-on, it asks you to re-authenticate with your provider where the task requires it.