> ## Documentation Index
> Fetch the complete documentation index at: https://docs.firetone.com.au/llms.txt
> Use this file to discover all available pages before exploring further.

# What a supervisor can do

> Oversight that comes from scope rather than from extra powers, and the one line that says which of your screens is your team's and which is the whole tenant's.

A **team supervisor** is an agent plus oversight. Nearly everything the role
adds comes from **scope** rather than from a longer menu: the permission says
*may listen to recordings*, and which recordings is decided by whose team you
run.

You may run more than one team. Everything below means *your teams*, plural.

## The rule worth learning first

Two halves of the panel answer the scope question differently, and mistaking
one for the other is the commonest surprise in the role.

|                                                                                                                     | Narrowed to                          |
| ------------------------------------------------------------------------------------------------------------------- | ------------------------------------ |
| **Work**: call history, live calls, recordings, stage reports, campaign dispositions                                | the agents and numbers of your teams |
| **Everything else**: queues, contacts, conference rooms, satisfaction, voicemail, the directory, the knowledge base | the whole organisation               |

So you read every team's satisfaction scores and every colleague's contacts,
and you cannot open a call one of your agents did not take. That is
deliberate. The first is oversight; the second is somebody's conversation.

<Note>
  **A call the system cannot attribute is not one you may open.** Where
  FireTone cannot demonstrate a call belongs to one of your teams, it refuses
  it. "Cannot prove it is yours" resolves to no, never to yes.
</Note>

## What you are kept away from

| You cannot                                                                                     | Because                                               |
| ---------------------------------------------------------------------------------------------- | ----------------------------------------------------- |
| add or remove **team members**, or set a skill level                                           | rostering people is the organisation admin's          |
| set a **team budget**                                                                          | it is a commitment of the tenant's money              |
| start, stop or re-target a **campaign**                                                        | a campaign spends outbound minutes at machine speed   |
| create or edit a **conference room**, an **IVR flow**, a **process** or a **number's routing** | configuration, rather than running a shift            |
| read **billing**, **margin**, the **audit log** or platform **logs**                           | the tenant's commercial position is not the floor's   |
| use the **AI configuration** or an AI key                                                      | a key that bills by the token is the account holder's |

You read most of those. Processes, campaigns, flows, the knowledge base and
integrations are all visible to you and none is editable, which is the shape
the role is meant to have: see what is running, change who is on it.

## Refusals you will meet

* **404, not 403**, for anything outside your teams — a call, a recording, a
  live room. Whether something exists is itself information about somebody
  else's work.
* **403** on a screen you have no grant for at all. The panel hides those, but
  the hiding is a courtesy. The API is what refuses.

<Note>
  An API key you create is intersected with your own role, so a key can never
  do more than you can. Revoking you revokes your keys by construction.
</Note>
