Skip to content

Roles & permissions

Access in ServiceOps is role-based. A role is a named bundle of granular permissions (read tickets, manage SLA policies, update organization settings…), granted at one of three levels: the whole organization, a workspace inside it, or — for the platform’s own staff only — globally.

RoleForIn short
Organization OwnerThe account that owns the organizationEverything, including billing and deletion
Organization AdministratorPeople who configure the deskEverything operational: settings, users, integrations, AI
AuditorCompliance reviewersRead-only across the organization
Billing ManagerFinanceSubscription and invoices
RoleForIn short
Workspace ManagerTeam leadsRuns the workspace: tickets, KB, SLA, groups, reports
Support AgentTechniciansHandles tickets, writes KB articles
AgentJunior techniciansHandles tickets with a narrower scope
ViewerObserversRead-only
End UserYour own employeesCreates and follows their own requests, reads the KB
Customer Admin / Customer UserA customer company’s users (service providers)Portal access scoped to their own company’s tickets
  1. Open Users, select the person.
  2. Choose the role at the right level — organization-wide, or per workspace.
  3. Save. The change applies to their next request; no re-login needed.

Every permission is checked server-side on every request — hiding a button is a courtesy, never the security boundary. Agents’ visibility over tickets is additionally scoped: an agent sees the tickets they requested, are assigned to, or that belong to their groups, unless their role grants read-all. See Security.