Roles and Access Matrix
Find the person, find what they can do. Access in BareBones Ticketing does not come from one setting. It comes from several separate ones, and the product checks each on its own. Holding one does not imply another.
Roles and access explains this in prose. This page is the lookup table.
Department access levels
Most everyday access comes from these three levels, given per department.
| Level | What it lets you do in that department | What it does not let you do |
|---|---|---|
| View | Read the department's tickets, queues, and projects. | Change anything. |
| Work | Everything in View, plus ordinary ticket work: comments, status changes, assigning tickets. | Change the department's settings. Reach tickets in other departments. |
| Admin | Everything in Work, plus the extra department duties listed below. 1 | System-wide administration, or anything in another department. |
The levels build on each other, and each one applies only to the department it was given for. Admin in Sales gives you nothing in Facilities.
You are not given a level directly. You are put in a group, and the group is given a level in a department. If several groups give you a level in the same department, the highest one applies. 2
Everything else that grants access
| Who or what | What it lets them do | What it does not let them do |
|---|---|---|
| Anyone not signed in | Sign in. Accept an invitation as an external participant. Run first-time setup, but only while no administrator account exists yet. | See any ticket, queue, or setting. |
| Someone named on a ticket | See that one ticket, if they raised it, were copied in, or were added as a watcher or participant. | Work on it as an agent, see internal comments, or see anything else. |
| A Customer Area visitor | Use the customer service catalogue, see their own tickets, follow up on them, and return to the Customer Area. Their access lasts at most eight hours. 3 | Use Quick Ticket, search, preferences, approvals, projects, agent screens, or any administration screen. |
| A System Administrator | Administer the whole installation: settings, users, groups, departments, catalogue, workflows, mail, licensing, import, audit, and diagnostics. They also get Admin in every enabled department and access to every project. | Automatically work tickets, act as a requester, or decide approvals. Those are checked separately. |
| A named project manager | Look after the content of that one project. | Reach the department, see its tickets, or touch any other project. |
| Someone staffed in a project role | Be seen as filling that role, and see the project. | Run the project, edit routing rules, or open its tickets. |
| Someone linking a ticket to a project | Attach the ticket, if they have Work or better in the ticket's department and can already see both projects. | Assign anyone, staff the project, change routing rules, or reveal a project they cannot see. |
| A named approver | Decide the one approval they were asked for. Where the step is set up as regulated, that decision is the regulated approval and carries the electronic signature. | Open the queue or make the status change themselves. |
| A named second approver for a reveal | Approve one specific request to reveal redacted information. This can be a department manager of record, who does not need to be an administrator. | Browse the redaction list, open the ticket, or undo any redaction. |
| An external participant | Add public comments and see files marked safe for external viewing, on the tickets they were linked to. | Sign in as a staff member, use the requester portal, the queue, search, projects, or administration. |
| Operator, Auditor, Import Operator, Evaluator | Nothing. These are job labels this manual uses to say which instructions apply to you. | Anything. They are not settings in the product. |
Things people confuse with each other
Each row gives only what is in its middle column.
| This | Means | Does not mean |
|---|---|---|
| You can see a project | You can find it and read it. | You can open its tickets, staff it, or change its rules. |
| You can run a project | You can do the project management tasks the product provides. | You have access to a department or its tickets. |
| Someone is staffed in a project role | One named person fills one slot on one project. | A routing rule exists, or that person can open tickets. |
| A project-role routing rule exists | Tickets matching it get an owner, watcher, or participant. | Anyone is actually staffed, or has access. |
| A ticket is linked to a project | The two records are related. | The ticket has been reassigned. |
| A routing rule ran | The product evaluated it at creation, at a status change, or in a bulk run. | It fixed missing staffing, or made a change the person was not already allowed to make. |
Things that check you rather than permit you
| Mechanism | What it actually does |
|---|---|
| Step-up | Asks an administrator to confirm their identity again before a sensitive change. It confirms who you are. It does not decide what you may do. |
| The product-use check | Blocks changes when the licence is not in order. It never permits a change. |
| A group name arriving from your company's sign-in system | Feeds into the mapping that grants access. It is not access on its own. |
| A menu item, notification, label, or web address you can reach | Presentation only. It adds nothing. |
| Queue counts, filters, saved views, and the 250-row list | Ways of arranging records you can already see. They never show you a record you cannot. |
If you sign in with a local or company directory password, step-up asks for that password again. If you sign in through single sign-on, it asks you to re-authenticate with your provider where the task requires it.
Related pages
- Roles and access
- Glossary
- Routes and workspaces (administrators)
- Limits and scope