The Zendesk Agent Role
A Zendesk agent is a billable seat with permissions attached. Most confusion about Zendesk roles comes from conflating those two things.
Zendesk agent, end user, admin
Zendesk has three basic roles and everything else is a variation on them.
The single most common support question about Zendesk logins is somebody who exists as an end user trying to reach the agent interface. Same email, different role, and the door simply does not open. An admin fixes it in the People section in a few seconds.
What a full agent can do by default
On the standard agent role, a person can view and work tickets within the groups they belong to, add public and internal comments, change status, assign, apply macros, create tickets on behalf of a customer, and search across the tickets they can see.
What they cannot do by default is just as important: change triggers, automations or business rules, alter ticket fields and forms, add or remove other agents, or reach most of the Admin Center. Configuration is deliberately not an agent power, and that is the correct default even in a small team.
Merging and deletion sit in an awkward middle. Whether an agent can merge tickets or delete them depends on the role configuration, and on custom roles you can grant either independently. Worth checking before you assume, because a team where nobody can merge produces a queue full of parallel threads.
Light agents
A light agent is a colleague who needs to see and comment on tickets but never replies to the customer. Engineers, finance, product, account managers. They can read tickets in the groups they are given, leave internal notes, and view reporting, but they can't make a public comment or be assigned as the ticket owner.
The reason people care is licensing: light agents are included rather than billed as full seats, and they're how you give the wider business visibility of support without doubling the bill. Availability and the included count vary by plan, so confirm what your tier includes before you plan a rollout. There is more detail in the light agents guide.
The trap is subtle. Light agents cannot reply publicly, so when a light agent knows the answer somebody else has to relay it. If a third of your tickets end up relayed by hand, you've mis-scoped who should be a full agent.
Custom roles
On the Enterprise tiers you can build custom agent roles, and this is where the model gets genuinely useful. Permissions are granular: which tickets a role can view, whether it can edit tickets it doesn't own, whether it can merge, delete, redact, export, access Explore, publish help centre articles, or reach specific parts of the Admin Center.
Three roles cover most teams. A standard agent. A senior agent who can merge, delete and edit macros. And a read-only role for auditors, contractors and the people who ask for a login and then use it twice a year.
Resist building eleven roles. Every role is a thing somebody has to reason about at four in the afternoon when a new starter needs access, and role sprawl is how people end up over-permissioned by accident.
Groups do half the work
Roles say what a person can do. Groups say which tickets they can do it to. Together they define access, and teams routinely tune one while ignoring the other.
If your agents can see every ticket in the business, that's a group decision, not a role decision. For most companies it is the right call, because ticket visibility helps agents help each other. For anyone handling health, financial or HR data it is a compliance problem waiting to be found in an audit.
When an agent leaves
Downgrade rather than delete. Deleting an agent account can affect the history attached to it, whereas downgrading them to an end user or suspending the account preserves everything they ever wrote and frees the seat.
Then reassign their open tickets deliberately. Tickets assigned to a departed agent sit quietly in a view nobody watches, and the customer chases, and now you have a second ticket for a problem that was already being handled.
Frequently asked questions
How do Zendesk user roles and agent permissions fit together?
Zendesk user roles set what someone is: end user, light agent, agent, admin. Zendesk agent permissions narrow what that role can do, and on Enterprise you can build custom roles instead of accepting the defaults.
What is a Zendesk agent?
A team member with access to the agent interface who works tickets. Agents consume a paid seat, unlike end users and light agents.
What is the difference between a light agent and a full agent?
Light agents can read tickets and add internal notes but cannot reply publicly or own a ticket. They are included rather than billed as full seats, subject to plan.
Can agents merge tickets?
It depends on the role. Standard agents usually can, and on Enterprise custom roles merge and delete permissions are set independently.
How do I stop an agent seeing certain tickets?
Through groups and a custom role that restricts visibility to the agent own groups. Role alone will not do it.
Should we delete an agent who leaves?
Downgrade or suspend instead. It frees the seat, keeps their ticket history intact, and avoids surprises in reporting.
Unassigned tickets become duplicate tickets
Tickets stranded with a departed agent get chased on another channel. Ticket Merger spots the pair and merges them before two people reply.
Start free trial14-day free trial. No credit card required.