Roles & permissions
Access in ServiceOps is role-based. A role is a named bundle of granular permissions (read tickets, manage SLA policies, update organization settings…), granted at one of three levels: the whole organization, a workspace inside it, or — for the platform’s own staff only — globally.
The organization roles
Section titled “The organization roles”| Role | For | In short |
|---|---|---|
| Organization Owner | The account that owns the organization | Everything, including billing and deletion |
| Organization Administrator | People who configure the desk | Everything operational: settings, users, integrations, AI |
| Auditor | Compliance reviewers | Read-only across the organization |
| Billing Manager | Finance | Subscription and invoices |
The workspace roles
Section titled “The workspace roles”| Role | For | In short |
|---|---|---|
| Workspace Manager | Team leads | Runs the workspace: tickets, KB, SLA, groups, reports |
| Support Agent | Technicians | Handles tickets, writes KB articles |
| Agent | Junior technicians | Handles tickets with a narrower scope |
| Viewer | Observers | Read-only |
| End User | Your own employees | Creates and follows their own requests, reads the KB |
| Customer Admin / Customer User | A customer company’s users (service providers) | Portal access scoped to their own company’s tickets |
Assign a role
Section titled “Assign a role”- Open Users, select the person.
- Choose the role at the right level — organization-wide, or per workspace.
- Save. The change applies to their next request; no re-login needed.
How enforcement works
Section titled “How enforcement works”Every permission is checked server-side on every request — hiding a button is a courtesy, never the security boundary. Agents’ visibility over tickets is additionally scoped: an agent sees the tickets they requested, are assigned to, or that belong to their groups, unless their role grants read-all. See Security.