Managing app permissions and who sees what

Plan requirement

Subscription Any plan
Access Admin

Which agents get to see an app, and what the app itself can reach. Two very different questions.

Set it

  1. Open the app in Admin Center.
  2. Restrict it to specific groups or roles.
  3. Review what the app itself is permitted to do.
  4. Save, and check with an agent who should not see it.

Visibility: restrict it

An app relevant to one team should not appear for everybody. Every panel on the ticket screen competes for attention, and an agent who never uses an app still has to look past it.

What the app can reach

This is the more consequential half. An app is granted access to ticket data, and sometimes to user records, when it is installed.

That access is not narrowed by hiding the app from agents. Restricting visibility is an interface decision, not a security one.

Read what it asks for

At installation, an app states what it needs. An app requiring access to everything to display a phone number is asking for more than its job requires, and that is worth questioning.

Apps can write, not just read

Many update fields, add tags or create tickets. Worth knowing which of your apps do, because a misbehaving one changes data rather than merely displaying it.

Restrict admin-facing apps hard

An app that can change configuration should be visible to the two or three people who administer the account, not to every agent.

Recheck after role changes

Restrictions are tied to groups and roles. A reorganisation quietly widens or narrows who sees what, and nobody reports having gained an app.

See also

Was this article helpful?

0

Still stuck?

Our support team will take a look with you.

Comments

0 comments

Article is closed for comments.