Getting started

Roles & permissions

Open HelpDesk has two kinds of people: the agents inside a workspace, and the contacts who reach it from outside. This page sets out both, and the single line that separates managing a workspace from working in one.

The four workspace roles

Everyone on your team holds exactly one role.

Owner
The top of the workspace. Can do everything an admin can, and is the only role that can grant the owner role to someone else.
Admin
Manages the workspace: team and roles, the email channel, automations, SLA policies, macros, fields, API keys and the knowledge base — everything an owner can reach, except handing out ownership.
Agent
Works tickets. Reads and replies, sets status, priority, tags and assignment, and writes internal notes. Does not reach the settings area.
Viewer
Read-only. Sees tickets and reports but cannot reply or change anything. Useful for stakeholders who need visibility without touching the queue.

The management boundary

There is one line that matters: owners and admins manage the workspace; agents and viewers do not. Everything behind Settings — the team, the email channel, automations, SLA policies, API keys, the audit log, and write access to the knowledge base — is reserved for owners and admins. An agent or a viewer never sees it. The owner sits above the admin: an admin cannot change an owner's role or disable an owner's account.

Inviting and disabling agents

Managers invite teammates by email from Settings → Team. An invited person stays in the invited state until they sign in and accept; you can resend the invitation at any time.

You do not delete an agent — you disable them. Disabling revokes their access immediately (a disabled account can no longer sign in) but keeps everything they did: their past replies, notes and the tickets they handled stay exactly where they are, so history and reports stay intact. When you disable someone, the still-open tickets assigned to them are returned to unassigned so nothing sits with an inactive agent. A disabled account can be re-enabled later, which restores access without losing any of that history.

Portal contacts

Contacts are the people who write in. On the customer portal they come in two kinds.

Contact
The default. Once signed in, a contact sees their own tickets and can follow up on them.
Organization admin
A contact granted oversight of their organization. When the organization shares tickets, an org admin sees every ticket raised by its members, not only their own.
The owner is the only role that can make someone else an owner — an admin cannot. And no one can change their own role or disable their own account, so a workspace can never be left without its owner and you cannot accidentally lock yourself out. To hand a workspace over, the current owner promotes another member to owner first.

Where to go next

New to the product? Start with the Overview or get a request flowing in Your first ticket.