Step 5: Choose who can see the card
The card carries customer data from your CRM, so who sees it is a deliberate choice rather than a default. This step sets it, and the server checks it on every request rather than trusting the browser.
#The required permission
Choose the project permission a viewer must hold. The widest option is labelled "Anyone who can see the issue", and the option for agents explains itself: "Anyone with agent access. This is the audience the customer card is for."
The widest option is still narrower than it sounds. Every card placement is offered only in service management projects, and only to viewers with agent access. Choosing the widest permission cannot widen the audience past that, and no portal customer ever sees the card.
#Restricting to groups
Naming groups narrows the audience further. As the screen puts it, "A viewer now needs the permission above AND membership of one of these groups. Both, not either." Group names are matched without regard to case, and can be separated by commas or new lines.
#A few things worth knowing
Editing the group list applies straight away, but moving a person into a group can take up to fifteen minutes to let them see the card, because membership is remembered for that long.
The card is licensed-only. An unlicensed viewer sees nothing at all rather than an empty panel.
Restricting to a group nobody is in hides the card from everybody, and the card gives the viewer no explanation, because telling them what they are missing would leak that it exists.
#Related
Decide the audience before the card exists.
