Freshdesk Agent Roles

Freshdesk roles say what an agent may do. Scope says which tickets they may do it to. Confuse the two and your permissions model quietly stops meaning anything.

Two settings, not one

Every Freshdesk agent carries two independent permission settings. Almost every permissions problem I have watched a team argue about comes from treating them as a single dial.

Role is the verb list. Reply, edit, delete, merge, export, edit automations, manage billing. It's a bundle of privileges you attach to a person.

Scope is the noun list. All tickets in the account, only tickets belonging to their groups, or only tickets assigned to them personally. Scope has nothing to do with role. An agent can hold a powerful role and still see almost nothing, and a junior agent on the weakest role can be handed visibility of every ticket in the business.

Set both. Deliberately. On purpose. The default combination is fine for a five-person team and wrong for a fifty-person one.

The default Freshdesk roles you get

Freshdesk ships with a small set of roles out of the box, broadly along these lines. Names and the exact privilege split have shifted between plans and releases, so treat this as the shape rather than gospel and check the current Freshworks docs for your account.

Account Administrator. Everything, including billing and the subscription. This should be one or two people. Not five.
Administrator. Full configuration control, usually short of billing. Automations, fields, SLAs, portal, apps.
Supervisor. Ticket work plus reporting and the ability to manage other people's work, without the keys to the configuration.
Agent. Handle tickets. Reply, resolve, add notes, use canned responses. No settings.

That ladder is genuinely well designed. Most teams need nothing more than these four for a long time.

Scope is the setting people get wrong

Three options, and the middle one is right far more often than either extreme.

Global. Sees every ticket in the account. Correct for admins, supervisors, and small teams where everyone genuinely helps with everything.
Group. Sees tickets belonging to the groups they're a member of. This is the right default for most agents in most teams.
Restricted. Sees only tickets assigned to them.

Restricted sounds tidy and behaves badly. An agent on restricted scope cannot see the ticket a colleague is already answering, cannot pick up the unassigned queue, and cannot check whether the customer in front of them wrote in yesterday about the same thing. That last one costs you real money, because two agents answering the same customer independently is how a support team produces contradictory answers.

Use restricted for outsourced contractors and for people who genuinely should not read other customers' conversations. Not as a general tidiness measure.

Custom roles and when they earn their keep

Custom roles let you build a privilege bundle that isn't one of the defaults. Availability is plan dependent, so check the current Freshworks docs before you design a structure around them.

Four cases where they are worth the effort:

The reporting-only stakeholder. A product manager or a finance lead who needs dashboards and nothing else. Give them reports and no ticket actions.
The senior agent who should not delete. Merge, edit, reassign, escalate, yes. Delete, no. Delete is the one action that generates a support ticket to Freshworks when it goes wrong.
The automation owner. Someone who maintains automations and canned content without holding full admin over billing, security and user management.
The QA reviewer. Global read across tickets, no ability to reply, so they can score conversations without accidentally sending one.

What custom roles are not for: making an org chart. If you find yourself building a role per team, stop. That's what groups are for.

Least privilege that survives a Tuesday

Least privilege gets a bad name because people implement it as a lockdown and then spend six months unlocking things one panicked Slack message at a time. Do it the other way round.

Start from what the job needs on a normal day, then add the exceptions someone actually asked for.

A recipe that holds up for a team of ten to fifty. Two account administrators, one of whom isn't the person most likely to be on holiday. Two or three administrators who can change configuration. Team leads on supervisor with global scope, because they need to answer "where is that ticket". Everyone else on agent with group scope.

Then the three specific removals worth making early. Take delete away from everyone except administrators. Take export away from anyone without a business reason, because a full ticket export is a customer data file walking out of the building. And keep automation editing to the people who understand what a rule loop does.

The audit nobody runs

Once a quarter, list every agent with global scope and every agent with an administrator role, and ask out loud why each one has it.

You'll find at least one person who was given admin for a two-week project in 2024. You'll find a departed contractor. And you'll probably find that half your agents can delete tickets, which is one bad afternoon away from being a problem. It takes twenty minutes.

FAQ

Frequently asked questions

How do Freshdesk permissions and scope differ?

Freshdesk permissions say what an agent may do; Freshdesk agent scope says which tickets they may do it to. Global, group and restricted scope are the three settings people get wrong.

What is the difference between a role and a scope in Freshdesk?

Role controls the actions an agent can perform, such as replying, deleting or editing settings. Scope controls which tickets those actions apply to: all tickets, group tickets, or only their own. They're set separately.

Can I create custom roles in Freshdesk?

Custom roles exist, but availability depends on your plan tier. Check the current Freshworks docs for which plan includes them before you design your permission structure around custom roles.

What scope should a normal support agent have?

Group scope, in almost every case. Restricted scope hides the ticket a colleague is already handling and prevents agents picking up unassigned work, which causes more problems than it solves.

How many administrators should an account have?

Two account administrators and a small handful of administrators. The common failure is an account where a third of the agents hold admin because it was easier than working out which privilege they actually needed.

Does changing an agent role affect their existing tickets?

Tickets stay where they are. What changes is what that agent can see and do next time they log in, so narrowing scope can make previously visible tickets disappear from their views.

Permissions do not stop duplicates

Even a perfectly scoped team gets two tickets for one problem. Ticket Merger finds the pairs and merges them automatically, on Zendesk and Freshdesk.

Start free trial

14-day free trial. No credit card required.