User tokens (admins)
Every user's personal access tokens — owner, label, access level, scope and dates — never the secret. This is the list for periodic access review; each person manages their own tokens under Tools › Tokens.
Reading the list
- Used by — AI agent or script (a person's own script, or the person). An agent's token can never approve or send anything, regardless of its access.
- Access — per area: which areas it reads and which it can change (cases, correspondence, time, library, broadcasts, messages, reporting, administration), capped by the owner's role.
- Status — active, with an idle flag after 14 days unused; or revoked, with when and why (a user's tokens are revoked on deactivation).
Acting on a token
Revoke stops it immediately; the owner sees it as revoked on their own Tokens page. There is no undo — they create a new one.
Export (CSV, XLSX or JSON, with a time zone and row count) for the review record.
Filters: owner or label, the owner's entity, access, status.