Staffing your desk: agent clearances
A permission grants a verb. A clearance grants a scope. Both are required independently, and your own row is the one row you can never change.
An invited staff account can sign in, load the desk, and see nothing — and that's correct, not a bug, until someone gives them at least one clearance here. This screen is what makes an invitation into someone who can actually work a queue.
Two ceilings, and both have to clear
A permission grants a verb — take a conversation, read a transcript. A clearance grants a scope — this department, up to this data-sensitivity class. Both are required independently, and a gap in either fails closed on its own: a transcript-view permission with no welfare clearance opens nothing, and a welfare clearance with no scope attached opens nothing either. The roster shows clearances as real data rather than implying access from a role alone, because "no clearance" isn't a cosmetic state — it's an agent who signs in and is shown zero conversations.
Granting a clearance
- Find the person by their directory identity.
- Pick a department and the data-class ceiling they may see within it.
- Confirm — and wait. The row doesn't update until the change is actually confirmed over the same live channel the desk itself uses; nothing here flips optimistically and quietly reverts if the server refuses it.
Your own row doesn't move
Every control on your own row is disabled, and the screen names why rather than hiding the row outright — a control that silently vanishes teaches nothing. The server refuses a self-grant and a self-standing change in either direction: an administrator who could widen their own clearance effectively holds every clearance, and one who could lift their own suspension was never really suspended. Even lowering your own access is refused, for the same reason in reverse — dropping yourself to zero with nobody else able to re-grant you would lock the desk out entirely.
If you need your own clearance changed, another administrator has to do it. That isn't a missing feature — it's the same rule everywhere else in this platform that a person cannot be the sole authority over their own access.
Roles (platform-wide scope, set on the staff-roles screen) and desk clearances (department-level, set here) are independent by design — check both when someone changes position, since closing one door doesn't close the other.