Access to the Help Desk is controlled by ISO Mate’s role-based access control (RBAC). You assign granular permissions to roles, and users inherit those permissions from the roles they hold. The Help Desk covers four permission sets, one each for tickets, canned responses, SLA policies, and auto-assignment rules, and every set follows the same view, create, update, and delete pattern.
Available permissions
Tickets
- ticket.view: view tickets, the ticket list, the Kanban board, and ticket details.
- ticket.create: create new tickets.
- ticket.update: edit ticket fields, add replies and internal notes, change status, assign agents, manage watchers, merge tickets, and link entities.
- ticket.delete: delete tickets.
Canned responses
- canned_response.view, canned_response.create, canned_response.update, and canned_response.delete: view, create, edit, and delete reusable reply templates.
SLA policies
- sla_policy.view, sla_policy.create, sla_policy.update, and sla_policy.delete: view and manage the service level commitments that drive SLA targets on tickets.
Auto-assignment rules
- auto_assignment.view, auto_assignment.create, auto_assignment.update, and auto_assignment.delete: view and manage the rules that route tickets to agents.
All Help Desk permissions are gated, which means they are granted only through a role rather than being available to every user by default.
Configure permissions
- Open Roles & Permissions from the Settings menu (the gear icon) in the top toolbar.
- Select a role to edit, or create a new role.
- In the permissions section, open the Help Desk group, which contains the Tickets, Canned Responses, SLA Policies, and Auto-Assignment Rules categories.
- Toggle the permissions you want to grant for each category.
- Click Save.
How permissions gate the UI
- Without ticket.view, the Help Desk group is hidden from the sidebar.
- Without ticket.create, the Create button is hidden on the ticket list and Kanban board.
- Without ticket.update, edit controls, the reply composer, status changes, watchers, merge, and entity linking are hidden on the ticket detail page.
- Without ticket.delete, delete buttons are hidden from ticket actions and bulk operations.
The same pattern applies to canned responses, SLA policies, and auto-assignment rules, where the matching view, create, update, and delete permissions control the corresponding pages and buttons.
Related permissions
Some Help Desk actions rely on permissions from other modules:
- Creating an issue from a ticket: requires the DevOps issue create permission, since it creates a real issue and links it back.
- Entity linking: linking to a task, incident, or email uses your access to those modules.
- Shared mailbox replies: sending a reply from a shared mailbox depends on having a shared mailbox connected and available to you.
Recommended role configurations
- Support agent: grant ticket.view, ticket.create, and ticket.update, plus canned_response.view so agents can work tickets and reuse templates without deleting records.
- Support manager: grant all four ticket permissions, full canned response permissions, and the SLA policy and auto-assignment permissions to configure the Help Desk.
- Read-only viewer: grant only ticket.view for stakeholders who need visibility without editing.
Related articles
Feature
Want to give your team the right level of access? Start your free 14-day trial.