SupportHubCX Platform Docs
v1.0.0 Public Support Open App

Roles & Permissions

SupportHub uses Spatie Permission. The seeded Admin role receives all permissions. The seeded Agent role receives the core ticket, organization, playbook, issue group, context hub, notification, and activity log permissions needed for day-to-day support work.

Role Management

  • /roles lists roles.
  • Users with create, edit, or delete role permissions can manage roles.
  • Role changes are reflected in the permission-aware sidebar and route middleware.

Permission Glossary

/permissions shows the permission glossary. Admins can update glossary metadata such as title, description, module, risk, sort order, and visibility. This keeps permission explanations understandable for buyers and administrators.

Permission Groups

GroupExamples
Settings and Toolsedit settings, use tools
Securitytotp setup, manage enterprise identity, impersonate users
Notificationsview notifications, manage notifications, view activity logs
Roles and Usersview/create/edit/delete roles, view permissions, view/create/edit/delete users, assign user roles
Ticket Setupmanage categories, priorities, statuses, SLA policies, tags, custom fields, mailboxes, business hours, reply templates, FAQ entries
Ticketsview, create, assign, reply, notes, status, priority, bulk, merge, split, time tracking
Case Filesview case files, manage case files, delete case files, view sensitive case files, export case files
Customersview/manage organizations and support contracts
Playbooks and Automationview/manage playbooks, work ticket playbooks, view/manage automations
Reportsview reports, export reports, manage report schedules
Integrations and Operationsmanage API clients, manage webhooks, view operations center, manage recovery suite

Least Privilege

Do not give every user the Admin role. Start agents from the Agent role, then add permissions only when a workflow requires them. Treat role assignment, settings, API clients, recovery, impersonation, identity, export, and delete permissions as sensitive.

The sidebar checks permissions before showing menu groups. Missing menu items usually mean the user lacks permission, not that the route is missing.

SupportHub roles directory
Audit role assignments before investigating a hidden module.
SupportHub permission glossary
Match each CX responsibility to the narrowest required permission.