Roles & action access
Action access controls what a role can do within an account. For example, you can let Team Leads mark tickets stale in one account while reserving that action for Admins in another.
A role's features control access to pages such as chats, tickets, and settings. Its actions control individual operations. Being able to view all tickets does not automatically grant permission to reassign or close them.
Configure a role
You need access to role management through System Settings.
- Select the account whose permissions you want to change.
- Open Teams → Roles and edit a role, or create a custom role.
- Review its feature permissions, then scroll to Action access.
- Select the actions this role should be allowed to perform.
- Save the role. The change applies to everyone assigned that role in this account.
The Admin role retains all actions; its permissions cannot be edited and the role cannot be disabled. Other predefined roles and custom roles can have their own action selections. Custom roles start with no actions selected.
Example: let Team Leads mark tickets stale
In Account A, edit Team Lead, select Mark stale / spam, and save. In Account B, edit the same role, clear that action, and save. Admins retain access in both accounts. Check other roles in Account B too if the action should be exclusive to Admins.
Changes are enforced on the next request. Controls refresh after a local role edit and otherwise refresh periodically, normally within 30 seconds. Refresh the page if a control still shows the previous access.
Available actions
There are 31 permissions, grouped in the role editor. Each row below is one permission.
Ticket lifecycle
| Action | Allows |
|---|---|
| Mark stale / spam | Mark work that is no longer relevant as stale. |
| Resolve ticket | Resolve a ticket, subject to assignment and ownership restrictions. |
| Reopen ticket | Return a closed, resolved, or stale ticket to the queue. |
| Close as duplicate | Select the original ticket and close the duplicate. |
| Mark awaiting response / schedule closure | Put a ticket into an awaiting-response flow, including scheduled resolution or closure. |
| Reactivate / cancel scheduled closure | Remove awaiting status or cancel a pending awaiting-response action where supported. |
| Snooze / unsnooze | Set or remove a ticket snooze. |
Assignment
| Action | Allows |
|---|---|
| Assign an unassigned ticket to yourself | Take an unassigned ticket as your own work. |
| Assign an unassigned ticket to an agent | Assign an unassigned ticket to another agent. |
| Reassign an assigned ticket | Change the agent on an already-assigned ticket, including taking it over yourself. |
| Unassign agent | Remove the current assignee. |
| Assign team | Set a team on a ticket that has no team. |
| Change team | Replace the current team. |
| Remove team | Clear the ticket's team. |
| Set / transfer / remove owner | Manage the parent ticket's owner, subject to the ownership rules below. |
Self-assignment does not allow taking someone else's assigned ticket. That requires Reassign an assigned ticket. Agent eligibility, channel, team, and ticket-state restrictions still apply.
Ticket creation and editing
| Action | Allows |
|---|---|
| Create ticket | Create a ticket manually or add one to the queue. |
| Create child ticket | Add child work to an eligible parent ticket. |
| Create interaction ticket | Create an interaction ticket for eligible pending backend work. |
| Edit tags, disposition and resolution drafts | Update these ticket fields without resolving the ticket. |
| Link / change / reevaluate order | Update or reevaluate the order linked to a ticket. |
Customers and email
| Action | Allows |
|---|---|
| Manage whitelisted domains | Add or remove domains from the whitelist. |
| Manage blacklisted domains | Add or remove domains from the blacklist. |
| Mute / unmute customer | Change customer mute status. If the control also changes AI mode, both permissions are required. |
| Change AI / manual mode | Switch the customer's conversation handling between AI and manual mode. |
| Overwrite customer name, email or phone | Change existing customer identity values. Filling an empty identity field remains subject to the existing customer-editing rules. |
| Merge customers | Merge duplicate customer records. |
Domain permissions apply to changes made from the inbox and from settings. Editing domain lists in settings also requires the relevant settings access.
Sensitive and bulk actions
| Action | Allows |
|---|---|
| Delete ticket | Delete a ticket. |
| Export tickets | Export ticket data. |
| Bulk assignment / unassignment | Assign, reassign, or unassign multiple tickets, with the corresponding individual action permissions. |
| Bulk resolution | Import bulk ticket actions, with Resolve ticket access; rows that snooze tickets also require Snooze / unsnooze. |
| Bulk order reevaluation | Reevaluate orders in bulk, with Link / change / reevaluate order and access to all tickets. |
A bulk permission alone does not grant the underlying individual actions or expand which tickets you can access.
Defaults and existing accounts
| Role | Default action access |
|---|---|
| Admin | All actions. |
| Agent, Senior Agent, Backend Agent, Senior Backend Agent | Resolve, awaiting response, reactivate, snooze, create tickets and children, edit ticket fields and orders, mute customers, and change AI mode. Existing ticket restrictions still apply. |
| Team Lead | The operational actions above, plus mark stale, reopen, close as duplicate, create interaction tickets, edit existing customer identity, and export. |
| Analyst | Export only. |
| New custom roles | No actions until explicitly configured. |
| Existing custom roles without saved action selections | Compatibility permissions based on their existing page access and the account's assignment settings; see below. |
For predefined roles, whitelisting, blacklisting, customer merge, ticket deletion, and bulk actions start with Admin access.
Existing custom roles without saved action selections retain compatibility permissions: ticket pages grant ordinary ticket work, export, spam marking, and bulk resolution; chat pages grant mute, AI mode, and whitelisting; Contacts grants customer merging. System Settings grants domain settings and, with ticket access, bulk assignment and order reevaluation. This fallback does not grant ticket deletion, reopening, duplicate closure, interaction creation, or overwriting customer identity. Review and save the selections to set an explicit policy for the role. New custom roles and roles explicitly saved with every action cleared remain empty.
For existing roles whose action access has not yet been saved, the account's previous agent reassignment and team-change settings contribute to the initial selections. Configure future changes in Teams → Roles → Action access. Once you save a role, its saved selections take precedence over those previous switches. Clearing every checkbox and saving denies all listed actions for that role.
Reset Role to Default restores both feature permissions and default action selections for a predefined role. It does not restore your last custom selection.
Restrictions that still apply
- Ownership: only the owner can resolve an owned parent ticket, even when an Admin has resolve access. Changing or removing an existing owner still requires the current owner or an Admin, as well as the owner-management action. See Ticket Ownership.
- Delegated work: child and interaction resolution still follows the existing assignee/Admin rules. Child creation and interaction creation have separate permissions and prerequisites.
- Ticket state: a permission does not make a resolved, blocked, or awaiting ticket assignable. Follow the normal ticket lifecycle.
- Account scope: the policy for the account that owns the record applies. One account's permission does not grant the same action in another account.
- Organization bulk operations: account-wide bulk checks require permission in every account in the current request scope. Select an individual account when its policies differ from the rest of the organization.
- Impersonation: actions use the impersonated person's permissions, without the operator's super-admin bypass.
- Queued work: revocation affects new requests; already-enqueued jobs retain their existing execution behavior.
In organization views, an explicit account role takes precedence for action access. Without one, an organization agent uses that account's Agent policy, an organization admin gets Admin defaults, and an organization viewer without account membership gets no actions.
The current version configures actions per role and account. It does not provide per-user exceptions or configurable own-ticket/team-wide action scopes.
Related
- Ticket View — work tickets and use their action controls.
- Agent Assignment & Teams — agent eligibility and routing.
- Agent Capacity — assignment limits and availability settings.
- Child & Interaction Tickets — creation and resolution prerequisites.