Skip to content

Inbox RBAC + SLA Operations Guide

Audience: Org admins, supervisors, and order operations users
Updated: April 2026

This guide explains the new role-aware inbox operations features: who can see what, how SLA policy works, and how supervisor/admin actions behave in the dashboard.


  • The inbox now uses capability-based RBAC for operations features.
  • Dashboard controls are role-scoped:
    • Supervisor operations
    • Admin governance
  • SLA policy updates are tracked in an audit-backed history panel.
  • Inbox controls now provide clearer permission feedback for unavailable actions.

  • Default personal inbox workflows.
  • Can act on work assigned to them.
  • Cannot access manager dashboard or admin SLA policy controls.
  • Can view team analytics dashboard.
  • Can run supervisor actions:
    • Escalate at-risk queue
    • Rebalance preview
  • Cannot edit org-level SLA policy unless explicitly granted admin capabilities.
  • Full supervisor access plus org governance controls.
  • Can update SLA threshold policy.
  • Can view org analytics surfaces.
  • Can assign work to teammates at org scope.

Open Inbox and select Dashboard (if available for your role).

Shows which capabilities are active for your account in the current organization and which are not granted.

Use this panel when teammates ask why certain controls are missing or disabled.

  • Escalate At-Risk Queue
    • Moves stale active items into awaiting_review.
    • Uses current SLA threshold as the at-risk cutoff.
  • Rebalance Assignments
    • Returns assignment load preview for team balancing decisions.
  • SLA Threshold (hours)
    • Configures SLA breach target for org inbox operations.
    • Valid range: 1 to 168 hours.
  • Recent SLA Policy Changes
    • Shows latest threshold changes from audit logs.
    • Includes actor and timestamp.

Permission-aware behavior in inbox actions

Section titled “Permission-aware behavior in inbox actions”
  • Assignment controls only allow teammate assignment when permitted.
  • Unauthorized bulk/keyboard actions fail fast with clear inline/toast feedback.
  • Server-side authorization still enforces final permissions for all endpoints.

Your account lacks the team analytics capability in the current organization role context.

Why can I assign to myself but not teammates?

Section titled “Why can I assign to myself but not teammates?”

Your role can process your own work but does not include teammate assignment capability.

In organization audit logs and surfaced in dashboard policy history.


  • Confirm correct organization is active.
  • Open Capability Visibility panel to verify active capabilities.
  • Ask org admin to review role metadata or role assignment.
  • If behavior still looks wrong, capture:
    • organization id
    • user id/email
    • attempted action
    • timestamp