Skip to content
English

Compartments

Compartments add a restrictive security boundary to cases. If a compartment is assigned to a case, anyone outside its access list is denied access even when another user, group, or administrator permission would normally let them see the case.

Think of a compartment as an additional allow-list around a case. nQuest evaluates it after ordinary case access: a person must already have permission to use the case and belong to every compartment assigned to it. Membership can be direct or inherited through an active group.

Common patterns include:

  • Deny by default for sensitive work. Create a compartment containing only the approved users and groups, then assign it when each case in the project is created. A compartment applies only to the cases to which it is assigned, so add it consistently to every case that needs the boundary.
  • Read-only projects. Put the approved audience inside the compartment, then give those people ordinary Viewer or Summary Viewer access to the cases. The compartment controls who may get through the boundary; the case role makes their access read-only. Do not make them owners or contributors.
  • Department or client boundaries. Add an established group to the compartment instead of maintaining the same people individually. Changes to active group membership then update who is inside the boundary.
  • Exceptional access. Add an individual directly when someone needs access outside the normal group structure. Keep direct exceptions limited so the access list remains understandable.

If a case has multiple compartments, a person must belong to all of them. This supports overlapping controls—for example, requiring someone to be approved for both a client and a sensitive workstream—but it can also exclude intended owners and contributors if the lists are not planned together.

Global Administrators can create compartments:

  1. Select New Compartment.
  2. Enter a name and a short name of up to 10 characters.
  3. Select Create.
  4. Add the users and groups that are allowed inside the compartment.

A user can be marked as a Compartment Admin, allowing that person to manage the compartment’s access list and settings without receiving Global Administrator permissions.

Add individual users when access is exceptional or the person must administer the compartment. Add a group when an established team should share the same boundary. Removing a user or group can immediately make compartment-protected cases inaccessible to them.

Global Administrators can manage every compartment. Compartment Administrators can open and manage compartments to which they are assigned, but they cannot create new compartments.

Before removing someone, review the cases protected by the compartment and reassign any ownership, contribution, delegation, or tasks that the person will no longer be able to perform.

  1. Open Compartments and select the compartment.
  2. Find the user or group in its access list.
  3. Select the remove control for that entry.

The change can immediately deny access to every case protected by the compartment. Removing a user directly does not deny them if they are still a member of an active group that is also on the compartment’s access list.

Compartment membership alone has no effect until the compartment is assigned to a case. Eligible case users add or remove compartments from the case’s access controls. Before applying one, confirm that every owner, contributor, delegate, and required viewer who still needs the case is inside the compartment.

Any member of a compartment who can edit the case can add it. Assign the compartment while creating the case or add it from the case details afterward.

To remove a compartment, you must be able to edit the case and be a Compartment Administrator for that compartment:

  1. Open the case and find Compartments in its details.
  2. Select the edit control beside the compartment list.
  3. Select the remove control on the compartment.

For the illustrated case workflow, see Compartments in Working with Others.