Skip to main content
The single most misread setting in Ravenna is workspace privacy. Teams make the HR workspace private, assume it is now invisible, and are surprised to find it listed in the Portal as a place anyone in the organization can file a request. That behavior is correct and useful. It is just not what “private” sounds like.

The two things people confuse

There are two independent axes, and neither one implies the other. Privacy scopes the shared ticket list. Visibility scopes the front doors. Turning one off does not turn the other off.

Private is not hidden

A private workspace with Available in Portal on still appears in the Portal. Anyone in your organization can select it, submit a request, and track their own ticket. What they cannot do is see the workspace’s ticket list or anyone else’s tickets. That is the intended design. It is how a sensitive team stays reachable without being readable.
To actually hide a workspace from everyone who is not a member, you need both: Private workspace on and Available in Portal off. Setting only the first leaves the workspace listed as a filing destination.
Two consequences worth internalizing:
  • Filing is not joining. A requester who submits to a private workspace becomes the ticket’s requester and follows that one ticket. They do not gain access to anything else.
  • Organization admin is not workspace access. Reaching a private workspace always requires being added as a member, org admins included.

Slack DM routing ignores both toggles

This is the other surprise.
Direct message routing follows agent presence, not visibility. Any workspace with an agent connected to its Slack channel can receive DM conversations, whether or not Available in Slack and Available in Portal are on.
So if you turn both visibility toggles off expecting the workspace to stop receiving requests, and it has a connected agent, DMs keep arriving. Disconnect the agent, or accept the intake.

The four gates on Portal visibility

Whether a given person sees a given workspace or form in the Portal is the AND of four settings at three different levels. Form audience settings apply on top of all of it. Only published forms whose audience includes the requester appear, and private folders stay hidden. If a requester says “I cannot see the form”, walk the list top down. It is almost always the form’s audience or its published state, not the workspace.
Learn more about what gates visibility

Use private tickets for one sensitive request

Workspace privacy is the wrong tool for a single sensitive item, because it is all or nothing. A private ticket restricts one ticket inside an otherwise busy workspace to its requester, assignee, followers, approvers, and the workspace’s members and admins. Note the last part carefully: every workspace member can see every private ticket in their workspace. Private tickets hide a ticket from the wider organization, not from your team. A grievance about a colleague who happens to be an IT workspace member is not protected by a private ticket in the IT workspace. It needs a private workspace with a restricted membership.
Learn more about private tickets and private notes

Decide it once, with this table

The second row is the one most teams actually want and the one most teams get wrong by leaving it at the third.

Before you turn the Portal on anywhere

Where teams get this wrong

It means unreadable. Turn off Available in Portal to hide.
DM routing follows agent presence, so a connected agent keeps the door open.
Every workspace member sees it.
Admins see workspaces and forms that requesters do not, so the Portal you tested is not the Portal they get.
It grants organization visibility you did not need to grant.

Next

Launch the Portal

The full Portal setup, once you have decided the privacy model.

HR and People desk

The private-by-default workspace built end to end.
Last modified on September 17, 2026