Roles & Permissions

Access to the helpdesk is controlled by the same role-based permission system as the rest of KarmaFlow. This article lists the helpdesk permission keys and shows how to compose useful support roles. Configure roles in Settings → Roles & Permissions.

Staff Permission Keys

These gate the internal (staff) helpdesk. Grant them to the roles your team members hold:

Permission Grants
View Tickets (helpdesk:tickets:read) See the ticket queue and open tickets
Create Tickets (helpdesk:tickets:create) Open new tickets
Edit Tickets (helpdesk:tickets:edit) Reply, change status/priority/assignee, merge, link
Delete Tickets (helpdesk:tickets:delete) Remove tickets
View Knowledge Base (helpdesk:kb:read) Read the KB admin
Manage Knowledge Base (helpdesk:kb:manage) Write, publish, and delete articles
View AI Approvals (helpdesk:approvals:read) See the AI Approvals queue
Review AI Approvals (helpdesk:approvals:manage) Approve or reject AI actions
Manage Helpdesk Settings (helpdesk:config:manage) Teams, SLA policies, portal, AI policy, categories

Reading Teams, SLA Policies, and Settings requires only View Tickets (agents need to see policy names and assignment options); changing them requires Manage Helpdesk Settings.

Admins and tenant admins hold every permission automatically — you don't need to enumerate keys for them.

Suggested Role Recipes

Build these in Settings → Roles & Permissions by checking the keys above, then assign staff to them.

Customer (Portal) Roles Are Separate

The permissions above govern your staff. Your customers are governed by a completely separate set of portal roles (member, power user, organization admin, billing admin, security admin, read-only viewer) that control what they see and do in the customer portal. Those are covered in Customer Portal and are managed per customer organization — they never mix with staff permissions.

A Note on Two Kinds of "Ticket"

If you also use KarmaFlow's built-in platform support (reporting problems to the KarmaFlow team from a record's comments), note that those "support tickets" are a different, unrelated feature from your customer-facing helpdesk tickets. The helpdesk permissions on this page apply only to your own customer support operation.