Helmdesk

Admin & Billing

Inviting team members and setting roles

Add agents and tenant users, and understand what each role can actually do.

Helmdesk has four roles, and they split cleanly into two groups: the people on your own team who run support, and the people at your clients who receive it.

The four roles

RoleWho it's forScope
super_adminYour platform-level administratorsCross-account
agentYour support staff who work tickets, chat, and the internal knowledge baseCross-account
tenant_adminAn admin at one specific client organizationThat organization only
tenant_userA regular user at one specific client organizationThat organization only

agent and super_admin aren't tied to any single client — the same agent can work tickets across every client organization your team supports. tenant_admin and tenant_user are scoped to one organization and can never see another's data.

What only agents and super admins can do

A handful of actions are restricted to your own team, regardless of how much access a tenant_admin otherwise has:

  • Assigning a ticket to a specific agent.
  • Posting an internal note on a ticket (visible to your team, never to the client).
  • Writing or editing internal-only knowledge base articles.
  • Signing in to the live chat console.

This split exists so a client's own admin account can manage their team's tickets and users without ever being able to see internal shorthand, assignment logic, or draft knowledge base content that isn't meant for them.

Inviting someone

From Settings → Users, click Invite user and set their email, name, and role. Since Helmdesk doesn't have outbound email wired up for every environment by default, an invite creates the account immediately and gives you a password-reset link to hand off to that person directly — there's no "pending invitation" email sent unless you're the one who sends it.

Deactivating someone

Deactivating a user (rather than deleting them) keeps their history intact — every ticket they touched, every reply they wrote, stays exactly as it was. A deactivated account simply can't log in anymore.

A note for tenant admins

If you're a tenant_admin inviting your own team, you can only invite tenant_user accounts — creating an agent or super_admin account is something only Helmdesk's own team can do, since those roles aren't scoped to your organization at all.