1. Purpose
To standardize the creation, assignment, and management of user roles within Zendesk and the WFM module, ensuring team members have the appropriate level of access to perform their duties while maintaining data security.
2. Zendesk Core Roles & Permissions
Standard Zendesk roles are categorized by their level of system control and ticket interaction.
| Role | Access Level | Key Permissions |
|---|---|---|
| Admin | Full | Manage Support/Talk settings; control ticket visibility. Cannot manage billing. |
| Agent | Standard | View and update tickets; full interaction with the Zendesk Home screen. |
| Light Agent | Limited | View tickets and add private comments only. Cannot edit or be assigned tickets. |
Note: Light Agent availability is subject to the Zendesk Growth plan or higher.
3. Custom Role Management (Enterprise Only)
Custom roles allow for granular control and should be used to align Zendesk with specific organizational hierarchies.
3.1 Custom Role Templates
Advisor: Manages workflows, automations, and SLAs.
Staff Agent: Focuses on ticket resolution and personal reporting.
Team Lead: Manages end users, groups, and forum moderation.
3.2 Creating and Assigning Custom Roles
Navigate to the Admin Center.
Select People > Roles.
Configure specific permissions (Ticket access, comment types, object management).
Save the role.
Assign agents via the Edit and Assign workflow. Role changes take effect immediately upon browser refresh.
4. Workforce Management (WFM) Roles
WFM roles manage operational efficiency, scheduling, and geographic distribution.
4.1 WFM Structure Definitions
WFM Admin: Full feature permissions; oversees teams, locations, and work streams.
Locations: Groups agents by geography or operational time zones (e.g., "Cape Town").
Work Streams: Defined by tags or regions to categorize work types (e.g., Email vs. Voice).
Teams: Groups reporting to a specific manager for shift trades and time-off approvals.
4.2 WFM Role Assignment Rules
Single Role Policy: Users can belong to only one WFM role at a time to prevent permission conflicts.
Scoped Access: When creating custom WFM roles, define the Scope to limit visibility to specific teams, locations, or work streams.
5. Best Practices for Governance
The Principle of Least Privilege: Assign the minimum level of access required for a user’s daily tasks.
Standardized Naming: While default roles can be renamed, they cannot be deleted. Maintain consistent naming conventions for custom roles to aid onboarding.
Real-Time Audits: Review role assignments during agent offboarding or internal transfers to ensure access is updated.
Immediate Refresh: Advise users to refresh their browser immediately after a role change to sync permissions.
6. Troubleshooting & Support
Permission Mismatch: If a user cannot see a specific Work Stream, verify the Scope settings within their assigned WFM role.
Role Conflicts: If an agent requires elevated permissions temporarily, use a custom role rather than granting full Admin access.