Skip to content
HELP CENTER/AUDIT, SECURITY & COMPLIANCE/WHO CAN SEE WHATUPDATED 15 AUG 2026

Who can see what

How access is decided, and how to answer that question about a specific case.

Hendl Support · Updated 15 Aug 2026
On this page

Access is the intersection of two things: a role, which says what someone can do, and team membership, which says which cases they can see.

Someone with the Administrator role but no teams still sees no case data. Someone with the Officer role in three teams sees those three teams' cases and nothing else.

The order it is evaluated in

  1. Is the person active? A deactivated account sees nothing.
  2. Is the case in one of their teams, or assigned to them directly, or shared with them?
  3. Does their role permit the action they are attempting?

A no at any step is a no. There is no override that skips step two.

Digital workers inherit, they do not exceed

A worker acting on behalf of a person sees what that person sees. It cannot surface a case, a document or a field the requesting person could not have opened themselves.

This is worth stating plainly in a security review, because it is the question that gets asked: introducing agents does not introduce a new access path.

Answering "who could have seen this case?"

Open the case, choose Access. It lists every person with visibility right now and why — team membership, direct assignment, or an explicit share.

It answers could see, not did see. Reads are not logged, which is a deliberate scope decision and worth knowing before somebody asks you for a list of everyone who opened a case.

Reviewing access

Settings → People exports the current roles and team memberships as CSV, which is the artefact most access reviews want. Every change to that list is in the audit log with who made it.

Did this answer your question?
More in Audit, security & compliance