Inbox RBAC + SLA Operations Guide
Audience: Org admins, supervisors, and order operations users
Updated: April 2026
This guide explains the new role-aware inbox operations features: who can see what, how SLA policy works, and how supervisor/admin actions behave in the dashboard.
What changed
Section titled “What changed”- The inbox now uses capability-based RBAC for operations features.
- Dashboard controls are role-scoped:
- Supervisor operations
- Admin governance
- SLA policy updates are tracked in an audit-backed history panel.
- Inbox controls now provide clearer permission feedback for unavailable actions.
Role visibility model
Section titled “Role visibility model”Standard user
Section titled “Standard user”- Default personal inbox workflows.
- Can act on work assigned to them.
- Cannot access manager dashboard or admin SLA policy controls.
Supervisor
Section titled “Supervisor”- Can view team analytics dashboard.
- Can run supervisor actions:
- Escalate at-risk queue
- Rebalance preview
- Cannot edit org-level SLA policy unless explicitly granted admin capabilities.
Org admin
Section titled “Org admin”- Full supervisor access plus org governance controls.
- Can update SLA threshold policy.
- Can view org analytics surfaces.
- Can assign work to teammates at org scope.
Dashboard areas
Section titled “Dashboard areas”Open Inbox and select Dashboard (if available for your role).
Capability Visibility
Section titled “Capability Visibility”Shows which capabilities are active for your account in the current organization and which are not granted.
Use this panel when teammates ask why certain controls are missing or disabled.
Supervisor Operations
Section titled “Supervisor Operations”- Escalate At-Risk Queue
- Moves stale active items into
awaiting_review. - Uses current SLA threshold as the at-risk cutoff.
- Moves stale active items into
- Rebalance Assignments
- Returns assignment load preview for team balancing decisions.
Admin Governance
Section titled “Admin Governance”- SLA Threshold (hours)
- Configures SLA breach target for org inbox operations.
- Valid range:
1to168hours.
- Recent SLA Policy Changes
- Shows latest threshold changes from audit logs.
- Includes actor and timestamp.
Permission-aware behavior in inbox actions
Section titled “Permission-aware behavior in inbox actions”- Assignment controls only allow teammate assignment when permitted.
- Unauthorized bulk/keyboard actions fail fast with clear inline/toast feedback.
- Server-side authorization still enforces final permissions for all endpoints.
Why is the dashboard button disabled?
Section titled “Why is the dashboard button disabled?”Your account lacks the team analytics capability in the current organization role context.
Why can I assign to myself but not teammates?
Section titled “Why can I assign to myself but not teammates?”Your role can process your own work but does not include teammate assignment capability.
Where do SLA policy changes get recorded?
Section titled “Where do SLA policy changes get recorded?”In organization audit logs and surfaced in dashboard policy history.
Troubleshooting quick checks
Section titled “Troubleshooting quick checks”- Confirm correct organization is active.
- Open Capability Visibility panel to verify active capabilities.
- Ask org admin to review role metadata or role assignment.
- If behavior still looks wrong, capture:
- organization id
- user id/email
- attempted action
- timestamp