- Their , which is their baseline across the whole company.
- Their access to each , which controls what they can do inside a specific team’s space.
How access is decided
Access to a workspace depends on whether you were added to it, your organization role, and, for a workspace you were not added to, whether it is reachable through the Portal. Follow the questions from the top.- In a workspace you work in (as a workspace admin or member), you see the full : the queue, other people’s tickets, and everything you can edit.
- In a public workspace you don’t work in, you see the : a self-service home to file and follow your own requests. That Portal experience is requester access.
Organization roles
An organization role is a person’s baseline across the entire company account. Everyone has exactly one.Organization admins
Organization admins
- Manage , branding, and notification policies
- Manage integrations and
- Invite, edit, and remove organization members
- Reach every public workspace automatically
- Reach a private workspace only when added as a workspace member
Organization members
Organization members
- Reach every public workspace automatically (see workspace access for what that access includes)
- Reach a private workspace only when added as a workspace member
- Create new workspaces, unless your admin restricts creation to admins
Organization guests
Organization guests
- No automatic workspace access, even to public workspaces
- Reach a workspace only when explicitly added as a workspace member
- Use the to submit and track their own requests
- Interact with tickets where they are the requester, assignee, or follower
Workspace access
Every workspace is either public or private. What that setting controls is the queue: who can browse the workspace and see other people’s tickets in it.- Public: anyone in your company can open the workspace and submit a request to that team, with requester access. Good for teams that serve everyone, such as IT or People Ops.
- Private: only workspace members can browse the queue or see other people’s tickets. Good for sensitive teams such as HR, Legal, or Security.
Requester access (not a workspace member)
Requester access (not a workspace member)
- Create tickets in the workspace
- Add public comments to tickets
- See and track their own tickets (as requester, assignee, follower, or approver)
- Approve or decline tickets when they are an approver
- See other people’s tickets
- Edit ticket properties such as status, priority, or assignee (including assigning a ticket to themselves)
- Post private notes
- Move or delete tickets
- Use
- Open workspace settings
Workspace member
Workspace member
- See and work every ticket in the workspace, including
- Edit ticket properties, assign tickets, and post
- Use
- View workspace settings
- Change workspace settings
- Add, remove, or change the roles of other workspace members
- Delete the workspace
Workspace admin
Workspace admin
- Do everything a workspace member can
- Change (SLAs, statuses, tags, and more)
- Add, remove, and change the roles of workspace members
- Delete the workspace
Master capability matrix
The columns combine both layers. “Org Guest” is the organization role. “Requester access” is an organization admin or member in a public workspace they have not been added to. “Workspace Member” and “Workspace Admin” are the two roles you assign inside a workspace. allowed not allowedWho can edit a ticket’s fields
There is one rule for editing a ticket, and it is worth stating plainly:- Organization role does not grant it. An organization admin has no ability to edit fields in a workspace they have not joined, even a public one. Their org role controls organization settings and members, not ticket fields.
- Requester access does not grant it. Organization admins and members with requester access can create a ticket and add public comments, but they cannot change its fields, not even to assign it to themselves.
- Organization guests cannot edit fields. They can only participate through the ticket roles they hold (requester, assignee, follower, approver).
- Workspace admins and members can edit every field on any ticket in their workspace, including private tickets.
How requests reach a workspace
People rarely submit a request by opening a workspace and clicking New ticket. They use whichever surface is most convenient, and Ravenna routes the request to the right team for them. This works even for a private workspace they cannot open themselves:- A connected to the workspace
- A to the Ravenna app in Slack
- An email address that belongs to the workspace
- A that belongs to the workspace
- The , which reads the request and sends it to the best-fit team
Choosing the right access
Assign the least-privileged access that still lets people do their jobs.Keep internal employees as organization Members
Add only the team that works a queue as workspace Members or Admins
Use organization Guest for external people
Use a private workspace for sensitive teams
Examples
Common situations and the access that results.An employee files an IT request but is not on the IT team
An employee files an IT request but is not on the IT team
You want only the HR team to work HR tickets
You want only the HR team to work HR tickets
A contractor on a different email domain needs to file tickets
A contractor on a different email domain needs to file tickets
A new hire should triage tickets in the IT workspace
A new hire should triage tickets in the IT workspace