Plan requirement
| Subscription | Any plan |
| Access | Admin |
It depends on their ticket access, not on their group membership. Two settings people expect to be one.
The answer
An agent set to see all tickets sees every group's work, whether or not they are a member. An agent set to their own groups sees only those.
Group membership decides what is routed to them. Ticket access decides what they can open.
Why people ask
Usually because they discovered that an agent can read tickets from a team they have nothing to do with. That is the default access being broader than anybody chose, not a fault.
Check it like this
- Open the team member.
- Read their ticket access setting.
- Read their group membership.
Those two answer the question completely.
Group-based is the sensible default
Broad enough to collaborate, narrow enough that one compromised account does not expose the whole account. All tickets should be a decision about specific people.
Private groups are the exception
Tickets in a private group are hidden even from agents with access to all tickets. That is the only setting that overrides it, and it is what HR or legal work needs.
Check it after reorganisations
People move teams and keep the access from the old one. Nobody reports having too much access, so it is only found by looking.
Comments
0 comments
Article is closed for comments.