The rule worth learning first
Two halves of the panel answer the scope question differently, and mistaking one for the other is the commonest surprise in the role.
So you read every team’s satisfaction scores and every colleague’s contacts,
and you cannot open a call one of your agents did not take. That is
deliberate. The first is oversight; the second is somebody’s conversation.
A call the system cannot attribute is not one you may open. Where
FireTone cannot demonstrate a call belongs to one of your teams, it refuses
it. “Cannot prove it is yours” resolves to no, never to yes.
What you are kept away from
You read most of those. Processes, campaigns, flows, the knowledge base and
integrations are all visible to you and none is editable, which is the shape
the role is meant to have: see what is running, change who is on it.
Refusals you will meet
- 404, not 403, for anything outside your teams — a call, a recording, a live room. Whether something exists is itself information about somebody else’s work.
- 403 on a screen you have no grant for at all. The panel hides those, but the hiding is a courtesy. The API is what refuses.
An API key you create is intersected with your own role, so a key can never
do more than you can. Revoking you revokes your keys by construction.