Skip to main content

Roles Settings: SSN Permissions

Overview

Administrators can control which agents can view Social Security numbers (SSNs) in the Alloy dashboard. Permissions can be assigned through a role or configured for an individual agent.

SSN access has three levels:

Access level

What the agent sees

Full SSN

123-45-6789

Partial SSN

xxx-xx-6789

No SSN Access

xxx-xx-xxxx

The relevant permissions are located under Personally Identifiable Information (PII) → SSN:

  • Agent can view full SSN

  • Agent can view partial SSN

The full SSN permission provides access to the complete number and enables full-SSN searches. The partial SSN permission provides access only to the last four digits and enables last-four searches.

Important: SSN permissions control access to sensitive data. Grant only the level of access required for an agent’s job responsibilities.

Configure SSN permissions

Update a role

  1. Go to Settings → Roles.

  2. Click the three vertical dots menu (⋮) for the role you want to update.

  3. Locate Personally Identifiable Information (PII) section.

  4. Expand SSN.

  5. Select or clear the applicable permission:

    • Agent can view full SSN

    • Agent can view partial SSN

  6. Save the role changes.

Agents assigned to the role inherit its permissions. Permission changes apply immediately.

Update an individual agent

Administrators can also configure permissions for a specific agent from the agent-management area. Go to Settings → Agents, open the agent’s details, and update the applicable PII permissions.

Note: Alloy Support cannot change customer roles or agent permissions. An administrator at your organization must make these changes.

How SSN access appears

Full SSN access

Agents with Agent can view full SSN can reveal the complete SSN where supported.

Full SSN permission example

Partial SSN access

Agents with Agent can view partial SSN can reveal only the last four digits.

Partial SSN permission example

No SSN access

Agents without either SSN permission see the SSN fully masked.

Masked SSN permission example

Restricted functionality

SSN permissions affect more than the PII header. Some search controls, raw-response views, vendor-response views, and data panels are hidden or disabled when the required permissions are missing.

Evaluation details

In evaluation details:

  • SSNs are displayed according to the agent’s permissions.

  • The SSN velocity tooltip is unavailable when the agent cannot view the full SSN.

  • The Raw Response option is hidden unless the agent has the required PII access. Service raw responses are unavailable to agents without the required permissions.

  • The Other Data panel may be hidden because it can contain supplied data or vendor-response data, including PII.

Raw evaluation responses

Raw evaluation responses require both of the following permissions:

  • PII → SSN → Agent can view full SSN

  • PII → DOB → Agent can view full DOB

If either permission is disabled, the raw response is hidden. Alloy does not currently support displaying the raw response while masking SSNs within it.

Other Data

The Other Data section can contain supplied data and vendor-response attributes. Viewing or editing this section requires the relevant workflow and entity permissions, plus full SSN and full DOB access.

If an agent cannot see Other Data, verify that their role includes:

  • The required workflow and entity-view permissions

  • Agent can view full SSN

  • Agent can view full DOB

Rerunning an evaluation

When an agent does not have permission to view the full SSN:

  • The SSN remains masked in the interface.

  • The full SSN and last-four fields cannot be edited.

The exact controls displayed depend on the agent’s permissions and the page they are viewing.

SSN search behavior

Search options are permission-controlled:

  • Full-SSN search requires Agent can view full SSN.

  • Last-four search requires Agent can view partial SSN.

  • Search controls should not appear when the agent lacks the corresponding permission.

  • Requests made without the required permission are rejected.

This behavior applies to supported evaluation, review, application, and alert queue experiences.

Related articles

Did this answer your question?