> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ravenna.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Private tickets

> Restrict ticket visibility to specific roles for HR, security, and confidential requests so only the requester and assigned team members can view.

Private tickets restrict visibility to specific users, ensuring sensitive information stays confidential. Use private tickets for HR requests, security incidents, personal information, and other confidential matters.

<View title="Human" icon="user">
  ***

  ## Visibility and access

  Private tickets are only visible to users with specific <Tooltip headline="Ticket roles" tip="Roles that control access and permissions" cta="Learn about ticket roles" href="/documentation/tickets/roles">roles</Tooltip>:

  * **Requester**: The person who created or is the subject of the ticket
  * **Workspace admins**: All administrators of the workspace the ticket belongs to
  * **Workspace members**: Team members with access to the workspace
  * **Assignee**: The person responsible for resolving the ticket
  * **Followers**: Users explicitly added to follow the ticket
  * **Approvers**: Users assigned to approve the ticket

  <Info>
    Followers and approvers lose access to a private ticket when removed from their role, unless they are also a workspace admin or member.
  </Info>

  <Callout icon="link" color="#6B7280">
    Ticket roles sit on top of your organization and workspace access. For the full model, see [Roles and access](/documentation/platform/roles-access).
  </Callout>

  ***

  ## Create private tickets

  Tickets become private through two methods:

  <AccordionGroup>
    <Accordion title="Direct messages with Ravenna" icon="message-circle" defaultOpen>
      Tickets created from Slack direct messages with Ravenna are always private, regardless of any other settings.

      <Note>
        Microsoft Teams does not have a 1:1 DM entry point in the current beta. All Teams tickets originate from channel messages. Use [private forms](/documentation/tickets/forms/overview) to keep Teams-created tickets private. See the [Microsoft Teams integration overview](/integrations/microsoft-teams/overview).
      </Note>

      When you message Ravenna directly in Slack:

      * The ticket is automatically marked as private
      * Only authorized users can view the ticket
      * The conversation stays in your DM with Ravenna
    </Accordion>

    <Accordion title="Forms with private setting enabled" icon="lock">
      When a <Tooltip headline="Form" tip="Structured intake forms with custom fields" cta="Learn about forms" href="/documentation/tickets/forms/overview">form</Tooltip> has the private setting enabled, all tickets created with that form are private by default. This applies even when users interact with the form in a public channel.

      **Public channel behavior**: If a user triggers a private form in a public Slack channel (via slash commands or agents), Ravenna:

      1. Posts a message in the public thread confirming the ticket was created. The notice includes a deep link to the requester's DM with Ravenna so they can jump directly into the private conversation.
      2. Automatically moves the conversation to the user's DM with Ravenna
      3. Continues all ticket interactions privately in the DM

      This ensures sensitive information is never exposed in public channels, even if the request started there.
    </Accordion>
  </AccordionGroup>

  <Callout icon="link" color="#6B7280">
    Learn more about [configuring private forms](/documentation/tickets/forms/overview) to automatically create private tickets
  </Callout>

  ***

  ## Use cases

  Consider using private tickets for scenarios where confidentiality is important:

  <AccordionGroup>
    <Accordion title="HR requests" icon="briefcase" defaultOpen>
      PTO requests, benefits inquiries, complaints, and personnel matters that require confidentiality.
    </Accordion>

    <Accordion title="Security incidents" icon="shield-alert">
      Vulnerability reports, security issues, and incident response that must remain protected.
    </Accordion>

    <Accordion title="Personal information" icon="user-lock">
      Requests involving private data, personal details, or sensitive employee information.
    </Accordion>

    <Accordion title="Confidential business matters" icon="shield-check">
      Sensitive operational matters, executive communications, or strategic discussions.
    </Accordion>
  </AccordionGroup>

  <Info>
    Your organization may have different needs for private tickets based on your security policies and compliance requirements.
  </Info>

  ***

  ## Manage access

  ### Role-based access

  Access to private tickets is dynamic and based on <Tooltip headline="Ticket roles" tip="Roles that control access and permissions" cta="Learn about ticket roles" href="/documentation/tickets/roles">roles</Tooltip>:

  **Adding roles**

  * Adding someone as a follower, approver, or assignee grants immediate access to the ticket

  **Removing roles**

  * Removing a follower, approver, or assignee removes their access unless they have another qualifying role (workspace admin/member, requester, or assignee)

  **Workspace membership**

  * Workspace admins and members always have access to private tickets within their workspace, regardless of ticket-specific roles

  ### Mentions

  <Warning>
    @mentions in private tickets do not automatically add users as followers. You must manually add them as a follower, approver, or assignee to grant access.
  </Warning>

  ***

  ## Public thread protection

  When a ticket is moved to private, the original public request thread displays a notice indicating the conversation has been moved. If the ticket originated from a private form triggered in a public channel, the notice also includes a deep link that opens your DM with Ravenna in one click. If you reply in the public thread of a private ticket, Ravenna sends you a one-time ephemeral warning reminding you to continue the conversation in DMs instead.

  <Info>
    The ephemeral warning is only shown once per user per thread. After seeing the warning, your future replies in that thread will not trigger additional warnings.
  </Info>
</View>

<View title="Agent" icon="bot">
  ## Mental model

  A private ticket restricts the entire ticket's visibility to users with specific roles. Unlike a regular ticket (visible to anyone in the workspace), a private ticket is only accessible to the requester, assignee, followers, approvers, and workspace members/admins.

  Private tickets are different from private notes. A private ticket hides the entire ticket from unauthorized users. A private note hides a single message within an otherwise visible ticket.

  ***

  ## How tickets become private

  Two mechanisms create private tickets:

  1. **DM-created tickets**: Any ticket created from a Slack DM with Ravenna is automatically private. This cannot be overridden.
  2. **Private forms**: When a form has the private setting enabled, all tickets created with that form are private by default.

  When a private form is triggered in a public Slack channel, the system automatically redirects the conversation to the user's DM with Ravenna. A confirmation message is posted in the public channel with an embedded deep link that opens the requester's DM with Ravenna, so they can reach the private conversation in one click. All subsequent interactions happen privately.

  ***

  ## Access rules

  | Role              | Access to private tickets       |
  | ----------------- | ------------------------------- |
  | Requester         | Always                          |
  | Assignee          | While assigned                  |
  | Followers         | While following                 |
  | Approvers         | While assigned as approver      |
  | Workspace members | Always (within their workspace) |
  | Workspace admins  | Always (within their workspace) |

  Access is dynamic. Adding someone as a follower grants access immediately. Removing them revokes access unless they qualify through another role.

  Important: @mentions do not grant access. Mentioning a user in a private ticket does not add them as a follower or grant visibility. You must explicitly add them to a role.

  ***

  ## Public thread protection

  When a ticket is privatized, the public request thread receives a prominent notice that the conversation has been moved to a private ticket. If a user replies in this public thread, Ravenna sends an ephemeral warning to that user, directing them to continue in DMs. This warning is sent once per user per thread — tracked via metadata on the Slack thread so repeat replies do not trigger additional warnings.

  The flow:

  1. A ticket is converted to private (via DM creation, private form, or 🤫 emoji).
  2. The public request thread gets a `:lock:` notice indicating the conversation moved to private. When the ticket originated from a private form in a public channel, the notice also embeds a deep link to the requester's DM with Ravenna so the requester can open the private conversation directly from the public thread.
  3. If any user posts a reply in the public request thread, Ravenna sends them an ephemeral message warning them to use DMs instead.
  4. The user's ID is stored in the thread metadata (`warnedUserIds`) so they are only warned once.
  5. The reply is silently dropped — it is not processed as a ticket message.

  This prevents accidental information leakage in public channels when users do not realize the ticket has been made private.

  ***

  ## Constraints and gotchas

  * DM-created tickets are always private. There is no way to make a DM-created ticket public.
  * Private forms create private tickets even when triggered from public Slack channels. The system handles the redirect to DM automatically.
  * Workspace members and admins always have access to private tickets in their workspace. If you need to restrict visibility from workspace members, private tickets alone are not sufficient. Consider using a separate workspace with restricted membership.
  * Access changes are immediate. Adding or removing a follower/approver/assignee updates visibility instantly.
  * @mentions in private tickets do not grant access or send notifications to users who lack access.
  * Replies in the public request thread of a private ticket are not processed. The user receives a one-time ephemeral warning to continue in DMs.
</View>
