Note: Applicable only for accounts in which workspaces have been enabled, and have more than one workspaces created.
There are two types of permissions that can be granted to agents:
Account-wide permissions: Only admin roles can be granted at the account-wide level. Users with account-wide admin permissions can access global settings and workspace-specific settings of all non-restricted workspaces
Workspace permissions:
These access levels can be granted in workspaces the user has been added to:Across the workspace: Can be granted for admin or agent roles to perform the specified actions within the workspace
In Member and Observer groups in the workspace: Can be granted for agent roles to access data in groups the agent is explicitly added as a member/observer
In the groups: Can be granted for agent roles to access data only in specific groups within that workspace
For items assigned to them in the workspace: Can be granted for agent roles to access only the items assigned to the agent
In cases where the granted access levels are not valid, Freshservice automatically grants the next applicable access level or revokes those permissions.
Permissions elevated to ‘Across the workspace’ when granted at any other access level:
Create Problems/Change/Release
Create and edit Assets
View/create/edit/delete Purchase orders
Create/edit/delete Announcements
Permissions elevated to ‘Account-wide’ when granted at any other access level:
View/work/manage Projects
View Solutions tab
Permissions elevated to ‘Account-wide’ when granted ‘Across the workspace’:
View Requesters/Departments
View/edit/manage User reports
Permissions applicable only ‘Account wide’ and are revoked when granted at any other access level:
View/Edit/Manage Virtual Agent reports
Create/Edit/Delete Departments
Configure asset management
Edit/Delete Requesters
Assume requester identity
Configure Financial Management
Play God with Super Admin controls
Include Account Management
Granting an agent access to View/Edit/Manage reports in a particular workspace would automatically grant those permissions in all workspaces they are a part of. However, the data shown in the reports is restricted to the scope of their access within that workspace.
For example: If Sam is a part of the HR and IT workspace and is granted access to ‘View ticket reports’ in the HR workspace, his permissions would be as below:
He can view ticket reports across HR and IT workspaces
In the reports he can access, he can only view the ticket data for the groups he has access to within the HR and IT workspace
Click here to understand how to manage agents and grant permissions: