# Customer support access requirements

The component serves customers and support staff from one case table.

1. An authenticated customer may view or reply to a case only when the stored
   case names that caller as its customer.
2. A support worker may review the full case, including the private staff note,
   and may resolve it when every route to that workflow requires the `support`
   role.
3. The `/staff/quick-review` convenience route remains available, but it has
   the same role requirement as `/staff/review`.
4. Route declarations list every database operation their handlers perform.
5. The server engine supplies `Db` and the authenticated `Principal`. Browser
   principals on the worked-example page are test inputs to direct function
   execution; they do not authenticate an HTTP request.

`support-access-before.bosatsu` deliberately violates requirement 3 by
declaring the convenience route as an ordinary authenticated route.
`support-access-after.bosatsu` repairs that one route declaration without
changing the handlers, data policy, or useful workflow.
