The Zendesk Admin Role

One Zendesk admin is a single point of failure. Five is a configuration nobody understands. The honest number is two or three.

What a Zendesk admin controls

An admin can do everything an agent can, plus configure the account. In practice that means the whole of the Admin Center: channels, people and roles, ticket fields and forms, triggers, automations, macros, views, SLA policies, apps, API tokens, webhooks, security settings and branding.

It is a broad grant. A single trigger change can email your entire customer base, redirect every incoming ticket to the wrong group, or silence the notification customers rely on to know you received their message. None of those require malice, only a Friday afternoon.

The role above admin is the account owner, and there's exactly one. The owner holds billing, the plan, and the ability to close the account. Owners are admins too, but not every admin is the owner, and moving ownership is a deliberate act rather than a checkbox. Know who yours is before the person who set the account up leaves.

How many admins you should have

Two or three. One is a hostage situation the first time that person is on holiday and email routing breaks. Six is a configuration where nobody can explain why a trigger exists, because four different people built overlapping rules over three years.

What people usually want when they ask for admin isn't admin. It's one specific capability: publishing help centre articles, editing macros, running an export, managing views. On Enterprise, custom roles give you exactly that without handing over the business rules.

Content editor. Help centre publishing, no business rules.
Quality lead. Macros, views and Explore, no triggers.
Senior agent. Merge, delete and redact, no configuration.
Auditor. Read everything, change nothing.

On the lower tiers you cannot slice it that finely, and the pragmatic answer is fewer admins plus a change process rather than more admins plus hope.

The settings worth auditing

Once a quarter, an hour, and it pays for itself.

Email authentication. SPF, DKIM and DMARC on your support address. Broken authentication sends your replies to spam, and a customer who never receives a reply writes in again. This is the single most expensive misconfiguration in the product.
Triggers, in order. Read them top to bottom. Every mature account has at least one trigger that duplicates another, and one that fires on a condition nobody remembers.
API tokens and webhooks. Who created them, what they access, whether the integration behind them still exists. Old tokens belonging to former staff are the most boring security incident there is.
Admin and agent list. Anyone still active who left, and anyone holding permissions they no longer use.
Business hours and SLA policies. Everything time-based hangs off these, and they quietly go wrong when you open an office in a new timezone.
The suspended ticket queue. Somebody should be checking it daily, and in most teams nobody is.

Change management, at a sensible scale

You do not need a change board. You need three habits.

Write down what you changed and why, in one line, somewhere the next admin will find it. The Zendesk audit log tells you who changed a trigger, and it will never tell you why.

Test anything that notifies in a sandbox first, if your plan includes one. The failure mode of an untested notification trigger is emailing everybody, which is a bad afternoon and a worse week.

And never make a rule change during your busiest hour. Obvious, routinely ignored.

Where admin work meets ticket volume

A surprising share of ticket volume traces back to configuration rather than to customers. Aggressive suspension rules put first-time messages in a queue nobody reads, so the customer tries another channel. A help centre nobody can find means people email to ask about a ticket they already have. Broken email authentication means replies never arrive.

Each of those produces the same visible symptom: two tickets for one problem. Fixing the setting removes the cause, and merging handles what still gets through. Both halves are the admin job, and only one of them is on anyone checklist.

FAQ

Frequently asked questions

Is the Zendesk account owner the same as an administrator?

No. A Zendesk administrator configures the product, and Zendesk admin permissions cover almost everything. The Zendesk account owner is the single billing identity, and only that person can change plan or transfer ownership.

What can a Zendesk admin do that an agent cannot?

Configure the account: channels, roles, fields, triggers, automations, SLA policies, apps, security and the rest of the Admin Center.

What is the difference between an admin and the account owner?

There is one owner, who holds billing and the plan and can close the account. Admins configure everything else.

How many admins should we have?

Two or three. One is a single point of failure, and more than three tends to produce configuration nobody can explain.

Can I give someone partial admin access?

On Enterprise, through custom roles with granular permissions. On lower tiers the choice is closer to all or nothing.

Audit the settings, then merge the rest

Suspension rules, email authentication and a findable help centre remove the cause. Ticket Merger removes the duplicates that still arrive.

Start free trial

14-day free trial. No credit card required.