Queue permissions
Who can see a queue, add work to it, move work along, and change the queue itself, and how to limit a role to specific queues.
Queue permissions separate four jobs: looking, adding work, moving work, and changing the queue itself. This lets you give a scanning station the right access without handing over the whole queue.
Levels on the Roles page
The app is called Work queues.
| Level | Lets someone |
|---|---|
| No access | Not open Work Queues. |
| Can view | See the board and where every item stands. |
| Can work the queue | Scan items in and move them along stages. Includes adding items. |
| Full control | Everything above, plus creating, changing and deleting the queues themselves. |
The workspace owner holds every permission.
What each action needs
| You want to | Needs |
|---|---|
| See a queue, its board, items and report | View |
| Add items (load a manifest) | Add work (enqueue) |
| Scan, Move, release a claim | Move work (transition) |
| A scan that creates a new item (Create an item queues) | Move work and add work |
| Press a stage's action button | Move work, and Can run on Custom code |
| New queue, Edit, delete a queue or an item | Full control |
Adding is not moving
Adding work and moving work are two separate permissions on purpose.
- A scanning station can be allowed to put items in without being able to advance them.
- A supervisor can advance work without being able to invent it.
The simple levels on the Roles page bundle both into Can work the queue. To grant only one, use a role's Advanced statement editor. See Team and permissions.
Limit a role to some queues
A queue's key is what permissions point at. A role can be limited to one queue, for example the dock team gets Can work the queue on inbound-dock only. This is why the key cannot change after you create the queue.
What people without access see
- A queue you cannot view does not appear in the list. It looks as if it does not exist.
- A queue you can view but not change shows a permission error when you try.
- Record details on board cards come from the linked records, so a queue never shows a record or a field the person could not open directly.
Moves use the mover's permissions
- A stage's record update is written with the mover's permissions. If they cannot change that record, the move is refused.
- A stage's on-arrival function runs as the mover.
- An intake rule adds records regardless of who edited them.
Tips
- Give floor staff Can work the queue. Give supervisors Full control only if they edit queues.
- To give a stage button to someone, give them Can run on Custom code as well. See Limits and permissions.