Delegation boundary
Target, route, and expiry
- Fleet
- —
- Route preference
- —
- Allowed scope
- —
- Created
- —
Connecting…
Operate access, terminal, tunnel, and command workflows for support access grant.
Delegated device access
Preview resolves the device, route, coarse scope, approval, expiry, target state, and concurrency rows before a support session is queued.
No grant selected
Effective state and lifecycle evidence remain empty until a UUID identifies a tenant-visible record.
Loading authority data
Not found
The identifier may be wrong, deleted, or outside this operator’s tenant boundary.
Permission required
SupportAccess.Grant is required by the authority to preview, queue, and inspect these grants.
Authority unavailable
No cached grant or fabricated authorization is being substituted.
Invalid authority response
Delegation details stay hidden until the service returns the complete governed contract.
Current support access grant
Device —
Grantee, capabilities, and revocation not exposed
The current contract exposes one coarse scope, route, approval reference, and expiry. It has no revoke endpoint or device-agent session material. Fleet therefore cannot claim who receives access, enumerate effective permissions, or offer a revocation control.
Delegation boundary
Governance
—
—
Immutable request
CLI parity
Supply your configured SaaS URL and Firebase token outside Fleet.
——Authority activity
Loading current lifecycle evidence…
No support-access events are available.
Current grant state is available, but lifecycle evidence could not be loaded.
New support access grant
Preview is read-only. Queueing locks the authority-normalized target, coarse scope, route, approval, expiry, and concurrency rows.
Authority preview