Overview
Roles and permissions control what each team member can see and do in DeskDay.
Every team member is assigned a permission role that determines:
Which DeskDay sections they can access.
What actions they can perform.
Whether they can access all records or only records assigned to them.
Which Control Center settings they can manage.
DeskDay includes default roles, and organizations can create custom permission roles for additional access requirements.
Before you begin
Make sure you have permission to manage team members and access settings.
The account owner who created the DeskDay account is always assigned Super admin. The account owner's Super admin role cannot be changed.
To change the account owner, contact DeskDay Support at [email protected].
Default roles
DeskDay includes four default roles.
Role | Intended access |
Super admin | Full access across DeskDay, including Control Center and account administration. |
Admin | Broad operational access for managing service delivery and day-to-day configuration. |
Finance Admin | Access focused on billing, financial records, and related operational areas. |
Technician | Day-to-day service delivery with access primarily to assigned work. |
Default role permissions are predefined and cannot be modified.
Custom permission roles can be created when the default roles do not match your organization's access requirements.
Open roles and permissions
Open Control Center.
Go to Team & Access > Roles & Permissions.
Select Permissions.
The Permissions page displays:
Default permission roles.
Custom permission roles.
The description of the selected role.
Access assigned to each DeskDay module.
Team members assigned to the role.
Use the search field to find a specific role.
Understand access levels
DeskDay modules can use three access levels.
Full access
Provides access to all applicable records and management actions within the module.
For example, Full Access for Tickets allows a team member to view and manage all tickets.
Limited access
Restricts the team member to the data or actions relevant to them.
For example:
Tickets: View and manage assigned tickets.
Projects: View and manage assigned projects and associated tasks.
Tasks: View and manage assigned tasks and use team member chat.
The exact behavior of Limited Access depends on the module.
No access
Hides the module or related functionality from the team member.
For example:
No Ticket access removes access to the ticket section and related home-screen functionality.
No Project access removes access to projects and their associated tasks.
No Task access removes access to tasks and team member chat.
Common module access behavior
Tickets
Full access: View and manage all tickets.
Limited access: View and manage tickets assigned to the team member.
No access: Tickets and related ticket functionality are hidden.
Projects
Full access: View and manage all projects and associated tasks.
Limited access: View and manage assigned projects and their associated tasks.
No access: Projects and associated project tasks are hidden.
Tasks
Full access: View and manage all tasks and use team member chat.
Limited access: View and manage assigned tasks and use team member chat.
No access: Tasks and team member chat are unavailable.
Announcements
Full access: Create and manage announcements.
Limited access: Access is restricted according to the configured role.
No access: Announcements are hidden.
Quality Assurance
Full access: Access and manage Quality Assurance information.
Limited access: Access is restricted to the work available to the team member.
No access: Quality Assurance is hidden.
Timesheets
Full access: View and manage all applicable timesheets.
Limited access: Access the team member's own timesheet information.
No access: Timesheets are hidden.
Invoices
Full access: Create, edit, and manage invoices.
Limited access: View-only access where supported.
No access: Invoice functionality is hidden.
Contracts
Full access: Create, edit, and manage contracts.
Limited access: View-only access where supported.
No access: Contract functionality is hidden.
Recurring invoices
Full access: Create, edit, and manage recurring invoices.
Limited access: View-only access where supported.
No access: Recurring invoice functionality is hidden.
Reports
Full access: Access and manage reports.
Limited access: View-only access where supported.
No access: Reports are hidden.
Customers
Full access: Create, edit, and manage all customers.
Limited access: Access only the customers permitted by the role configuration.
No access: Customer functionality is hidden.
Control Center
Control Center access determines which organization, team, service desk, channel, billing, automation, and integration settings the team member can manage.
The available options depend on the permission role assigned to the team member.
View members assigned to a role
Open Control Center > Team & Access > Roles & Permissions > Permissions.
Select a role.
Click Members in the upper-right corner.
The members drawer displays the team members currently assigned to that role.
Use the search field to find a specific member.
You can also select Add new member to add another team member when required.
Create a custom permission role
Create a custom permission when the default roles do not provide the required access.
Open Control Center > Team & Access > Roles & Permissions > Permissions.
Click + Permission.
Custom permission creation uses two steps.
Step 1: Add permission details
Enter:
Permission: Name of the custom permission role.
Description: Explain what the role is intended for.
Click Next.
Use a clear role name that makes its purpose easy to identify, such as:
Tier 1 technician
Service desk manager
Billing specialist
Co-managed technician
Step 2: Configure access
DeskDay displays the available modules grouped by area.
For each module, select:
Full Access
Limited Access
No Access
Review all sections before completing the permission.
For example, a technician role might use:
Tickets — Limited Access
Projects — Limited Access
Tasks — Limited Access
Billing — No Access
Administrative Control Center sections — No Access
Complete the setup to create the custom permission.
The new permission becomes available for assignment to team members.
Update a custom permission
Custom permission roles can be updated when access requirements change.
Open the Permissions page.
Locate the custom permission.
Open its available actions.
Edit the permission configuration.
Update the required module access.
Save the changes.
Changes to a permission affect team members assigned to that permission.
Default DeskDay roles cannot be modified.
Duplicate an existing permission
An existing permission can be duplicated when you need a similar role with only a few access differences.
Open the actions for the required permission.
Select the duplicate option.
Update the permission name and description.
Adjust the required access levels.
Save the new permission.
This helps avoid configuring a similar custom permission from the beginning.
Assign a permission to a team member
Permissions can also be managed directly from the team member profile.
Open Control Center > Team & Access > Team members.
Select the required team member.
Open the Permission tab.
Open the Permissions dropdown.
Select the required role.
Save the change where required.
The page displays the effective access that comes with the selected permission.
Review the listed module access before assigning the role.
Review a team member's permission
The Team members table displays the current permission assigned to each team member.
The table includes information such as:
Name
Email
Manager
Permission
To review the detailed access:
Open the team member.
Select the Permission tab.
Review the assigned permission.
Review the access displayed for each module.
Default Role Permissions
Module | Super Admin | Admin | Finance Admin | Technician |
Tickets | Full | Full | Full | Limited |
Projects | Full | Full | Full | Limited |
Tasks | Full | Full | Full | Limited |
Announcements | Full | Full | No | Limited |
Quality assurance | Full | Full | No | Limited |
Timesheets | Full | Full | Full | Limited |
Invoices | Full | Full | Full | No |
Contracts | Full | Full | Full | No |
Recurring invoices | Full | Full | Full | No |
Reports | Full | Full | No | No |
Customers | Full | Full | Full | Full |
My Company | Full | No | Limited | No |
Account preference | Full | Limited | No | No |
Channels | Full | Full | No | No |
Service desk | Full | Full | No | No |
Contracts & billing | Full | Full | No | No |
Integrations | Full | Full | No | No |
Important notes
Every team member must have a permission role
The account owner is always a Super admin.
Default roles cannot be modified.
Custom permissions can be created for specific operational requirements.
Full, Limited, and No Access behavior varies by module.
Changing a custom permission affects all team members using that permission.
Changing a team member's permission changes what they can see and manage in DeskDay.
Review access carefully before assigning administrative, billing, customer, or Control Center permissions.
Troubleshooting
A team member cannot access a section
The correct permission is assigned to the team member.
The module is not set to No Access.
Limited Access does not restrict the record the team member is trying to access.
The team member has refreshed or signed in again after the permission was changed.
A technician cannot see a ticket
Ticket access is set to Full or Limited Access.
If Limited Access is configured, the ticket is assigned to the technician.
A team member cannot see a project or task
Project and task permissions allow access.
The team member is assigned to the project or task when Limited Access is configured.
Project access has not been set to No Access.
A default role cannot be edited
This is expected. DeskDay's default roles have predefined permissions.
Create or duplicate a custom permission when different access is required.
The account owner's permission cannot be changed
The account owner must remain a Super admin.
To change the account owner, contact DeskDay Support at [email protected].
A permission change is not visible
Ask the team member to refresh DeskDay or sign out and sign back in.
For assistance, contact DeskDay Support at [email protected].
