Freshdesk Agent Roles
Freshdesk roles say what an agent may do. Scope says which tickets they may do it to. Confuse the two and your permissions model quietly stops meaning anything.
Two settings, not one
Every Freshdesk agent carries two independent permission settings. Almost every permissions problem I have watched a team argue about comes from treating them as a single dial.
Role is the verb list. Reply, edit, delete, merge, export, edit automations, manage billing. It's a bundle of privileges you attach to a person.
Scope is the noun list. All tickets in the account, only tickets belonging to their groups, or only tickets assigned to them personally. Scope has nothing to do with role. An agent can hold a powerful role and still see almost nothing, and a junior agent on the weakest role can be handed visibility of every ticket in the business.
Set both. Deliberately. On purpose. The default combination is fine for a five-person team and wrong for a fifty-person one.
The default Freshdesk roles you get
Freshdesk ships with a small set of roles out of the box, broadly along these lines. Names and the exact privilege split have shifted between plans and releases, so treat this as the shape rather than gospel and check the current Freshworks docs for your account.
That ladder is genuinely well designed. Most teams need nothing more than these four for a long time.
Scope is the setting people get wrong
Three options, and the middle one is right far more often than either extreme.
Restricted sounds tidy and behaves badly. An agent on restricted scope cannot see the ticket a colleague is already answering, cannot pick up the unassigned queue, and cannot check whether the customer in front of them wrote in yesterday about the same thing. That last one costs you real money, because two agents answering the same customer independently is how a support team produces contradictory answers.
Use restricted for outsourced contractors and for people who genuinely should not read other customers' conversations. Not as a general tidiness measure.
Custom roles and when they earn their keep
Custom roles let you build a privilege bundle that isn't one of the defaults. Availability is plan dependent, so check the current Freshworks docs before you design a structure around them.
Four cases where they are worth the effort:
What custom roles are not for: making an org chart. If you find yourself building a role per team, stop. That's what groups are for.
Least privilege that survives a Tuesday
Least privilege gets a bad name because people implement it as a lockdown and then spend six months unlocking things one panicked Slack message at a time. Do it the other way round.
Start from what the job needs on a normal day, then add the exceptions someone actually asked for.
A recipe that holds up for a team of ten to fifty. Two account administrators, one of whom isn't the person most likely to be on holiday. Two or three administrators who can change configuration. Team leads on supervisor with global scope, because they need to answer "where is that ticket". Everyone else on agent with group scope.
Then the three specific removals worth making early. Take delete away from everyone except administrators. Take export away from anyone without a business reason, because a full ticket export is a customer data file walking out of the building. And keep automation editing to the people who understand what a rule loop does.
The audit nobody runs
Once a quarter, list every agent with global scope and every agent with an administrator role, and ask out loud why each one has it.
You'll find at least one person who was given admin for a two-week project in 2024. You'll find a departed contractor. And you'll probably find that half your agents can delete tickets, which is one bad afternoon away from being a problem. It takes twenty minutes.
Frequently asked questions
How do Freshdesk permissions and scope differ?
Freshdesk permissions say what an agent may do; Freshdesk agent scope says which tickets they may do it to. Global, group and restricted scope are the three settings people get wrong.
What is the difference between a role and a scope in Freshdesk?
Role controls the actions an agent can perform, such as replying, deleting or editing settings. Scope controls which tickets those actions apply to: all tickets, group tickets, or only their own. They're set separately.
Can I create custom roles in Freshdesk?
Custom roles exist, but availability depends on your plan tier. Check the current Freshworks docs for which plan includes them before you design your permission structure around custom roles.
What scope should a normal support agent have?
Group scope, in almost every case. Restricted scope hides the ticket a colleague is already handling and prevents agents picking up unassigned work, which causes more problems than it solves.
How many administrators should an account have?
Two account administrators and a small handful of administrators. The common failure is an account where a third of the agents hold admin because it was easier than working out which privilege they actually needed.
Does changing an agent role affect their existing tickets?
Tickets stay where they are. What changes is what that agent can see and do next time they log in, so narrowing scope can make previously visible tickets disappear from their views.
Permissions do not stop duplicates
Even a perfectly scoped team gets two tickets for one problem. Ticket Merger finds the pairs and merges them automatically, on Zendesk and Freshdesk.
Start free trial14-day free trial. No credit card required.