-
-
Notifications
You must be signed in to change notification settings - Fork 27
Confidential Tickets
Added in 2.8.0 Β· Asked for in discussion #62 Β· Developer guide
Some tickets are nobody else's business. Someone emails HR about a diagnosis and asks what benefits they can claim. Someone asks how to raise a grievance, and the grievance is about their own manager. A ticket marked Confidential is kept from the requester's managers.
Why this exists now. Portal managers can see the tickets raised by the people they manage. Confidential had to exist first, so that on the day managers are switched on, the tickets that must never reach them are already marked.
- It keeps a ticket from the requester's managers. Exactly what a manager sees of one is set on System β Managers: nothing at all (the default, not even that a confidential ticket exists), only that it exists, or everything. See Portal managers.
- It does not hide the ticket from the service desk. Analysts see confidential tickets exactly as before. Who on the desk can see a ticket is still decided by teams, departments and companies.
Analysts: set Sensitivity to Confidential in the ticket's properties, or on the new-ticket form. A confidential ticket shows:
- a red Confidential marker in the properties bar, even with the panel collapsed, so nobody works one without knowing;
- a padlock before its subject in the ticket list.
Requesters, in the self-service portal:
- turn on This is confidential when raising a ticket;
- or open one of their tickets and press Mark confidential.
They can make a ticket confidential, but never undo it. Only the service desk can make a ticket Normal again. Otherwise a requester could be talked into un-marking a grievance by the very manager it is about.
The dangerous moment is before anyone has read the ticket. A grievance emailed to HR would otherwise sit unmarked until an analyst got to it. So a ticket becomes confidential automatically when:
| When | Set up on |
|---|---|
| It arrives through a confidential mailbox, such as an HR mailbox | Tickets β Settings β Mailboxes β Tickets from this mailbox are confidential |
| It is in, or is moved into, a confidential department | Tickets β Settings β Departments β Tickets here are confidential |
| The requester turned on This is confidential | the portal |
| It is split from, or merged with, a confidential ticket | automatic |
For an HR mailbox, use the mailbox setting. An emailed ticket arrives without a department, so the department setting can't protect it until somebody files it. The mailbox setting protects it the moment it lands.
Turning a department confidential also marks the tickets already in it. Those are exactly the tickets the setting is for. A message says how many were marked.
Every automatic change goes into the ticket's audit trail with its reason, for example Confidential - arrived through the HR inbox mailbox.
Moving a ticket out of HR leaves it confidential. Switching a department's setting off leaves its tickets confidential. Only a person choosing Normal on the ticket lowers it, and the audit trail records who.
The reasoning: marking something confidential by mistake costs nothing. Unmarking it by mistake can't be taken back once a manager has read it.
Confidential keeps a ticket from managers. It also keeps it from leaving FreeITSM - an AI provider, a Slack channel or a Jira project is somebody else's system.
| Where it could go | What happens to a confidential ticket |
|---|---|
| AI features - the summary, Read it for me, reply clean-up, Ask AI, merge summaries, knowledge write-ups, WhatsApp/Slack channel summaries | Not sent. The feature says why instead. Tickets β Settings β General β Confidential tickets and AI can allow it (it is "never send" until changed). |
| AI that reads many tickets - problem root cause, suggested problems, knowledge gap analysis | Left out. |
| The war room bot | Still counted, but shown to the AI by number only - "Confidential ticket". |
| Webhooks, Slack, Teams (workflow Send webhook) | Always cut down to its number, status, priority, department and team; the subject reads "Confidential ticket", and the text and requester are not sent. Not a setting - a chat post cannot be taken back. The editor's Send test never uses a confidential ticket as its sample. |
| External trackers (Jira, Azure DevOps) | By hand: the escalation preview warns, and you must tick a box to say you mean it - the service desk may genuinely need a supplier's help. By a workflow: never - the action is skipped, and the run history says confidential. |
| A workflow's Send email (3.0.0) | Sent only to the ticket's requester or to analysts. Any other address - a manager, a shared list, an outside contact - is skipped, and the run history says why. The requester already knows what they wrote, and confidential never restricts the service desk. | | Calendars (3.0.0) - tickets synced into Outlook or a CalDAV calendar, and the subscribe (.ics) link | The event shows the ticket number and "Confidential ticket", with its time, status and priority, so the day still reads as booked. The subject and the requester's name stay in FreeITSM. A scheduled ticket already in a calendar is updated as soon as it becomes confidential. |
Before 3.0.0 these last two were not covered: Send email went to whatever address the workflow named, and a synced calendar showed the ticket's subject.
Run System β Database Verification once. Until then, everything works as before, but choosing Confidential is refused with a message asking you to run Verification. FreeITSM will never quietly save a ticket as Normal that someone asked to be confidential.
GET /api/v1/tickets/{id} returns "sensitivity": "normal" or "confidential". Send sensitivity on create or update to set it. See REST API: Tickets.
FreeITSM β an open-source IT Service Management platform Β· github.com/edmozley/freeitsm Β· MIT licence
- Installation
- β° Scheduled tasks (cron jobs)
- Architecture
- π§ͺ Developer tests
- AI Providers
- Internationalisation (i18n)
- Timezones & Time Handling
- π Date & Time Formats
- Theming & Dark Mode
- ποΈ Recent β getting back to what you were doing
- β¨οΈ Command palette (βK)
- π Searching inside tickets
- π Attached documents
-
MobileβFriendly
- β³ π« Mobile: Tickets
- β³ π» Mobile: Assets
- β³ π Mobile: Calendar
- β³ π Mobile: Knowledge
- β³ π¦ Mobile: Service Status
- β³ πΌ Mobile: Watchtower
- β³ π§© Mobile: Problem Management
- β³ π Mobile: Change Management
- β³ πΏ Mobile: Software
- β³ β Mobile: Tasks
- β³ π Mobile: Forms
- β³ π Mobile: Contracts
- β³ π Mobile: Domains
- β³ π Mobile: People
- β³ π Mobile: LMS
- β³ πΊοΈ Mobile: CMDB
- β³ πΊοΈ Mobile: Network Mapper
- β³ π§ Mobile: Process Mapper
- β³ βοΈ Mobile: Workflow
- β³ π₯οΈ Mobile: System
- β³ π Mobile: Reporting
- β³ π Mobile: System Wiki
- β³ π Mobile: Self-Service Portal
- β³ π§° Mobile: Techniques & Tricks
-
Security
- Layer 1 β which modules you can enter
- β³ π§© Module Access Control
- β³ π οΈ Module Access β Developer Guide
- Layer 2 β what you can administer
- β³ π Roles & Permissions
- β³ π οΈ Roles β Developer Guide
- β³ π€ Why capabilities are constants
- Layer 3 β the System module
- β³ π Admin Access Control
- Hardening
- β³ π Security review response 2026-08
- β³ π‘οΈ Security hardening 2026-08
- β³ π οΈ Security hardening 2026-08 β Developer Guide
- β³ π‘οΈ Round three β plain English
- β³ π οΈ Round three β Developer Guide
- β³ π‘οΈ CSRF protection (S4) β Developer Guide
- Single Sign-On (SSO)
- ποΈ LDAP & Active Directory
- π CardDAV contact sync
- Browser Extension
- API Reference
-
π REST API β how it works
- β³ π« REST API: Tickets
- β³ π» REST API: Assets
- β³ π΄ REST API: Problems
- β³ π REST API: Changes
- β³ π REST API: Knowledge
- β³ β REST API: Tasks
- β³ ποΈ REST API: CMDB
- β³ π REST API: Contracts
- β³ ποΈ REST API: Calendar
- β³ πΏ REST API: Software
- β³ π REST API: Domains
- β³ π¦ REST API: Service Status
- β³ βοΈ REST API: Morning Checks
- β³ π REST API: Forms
- β³ βοΈ REST API: Workflow
- β³ π·οΈ REST API: Cost centres
- β³ πΊοΈ REST API: Network Mapper
- β³ π§ Using the API docs page
- β³ π OpenAPI specification
- β³ β OpenAPI: kept correct
- β³ π οΈ Maintaining the catalogue
- Watchtower
-
Tickets
- β³ π Rota copy and paste β Developer Deep Dive
- β³ β Checklists & SOPs
- β³ βοΈ Mandatory fields
- β³ π·οΈ Ticket categories
- β³ π₯ Assigning tickets to a team, and escalation
- β³ π’ One board across every company
- β³ Mailbox Authentication
- β³ π€ Email send log
- β³ Basic IMAP mailboxes
- β³ Email rendering & images
- β³ SLA Management
- β³ WhatsApp channel
-
β³
βοΈ Telegram channel - β³ β CSAT company scope and filters β Developer Guide
- β³ π₯ Microsoft Teams channel
- β³ π¨οΈ Mattermost channel
- β³ π¬ Web chat channel
- β³ π£ Slack channel
- β³ π Linking tickets
- β³ β Record previews
- β³ π Ticket notes: internal or shared
- β³ ποΈ Canned responses
- β³ βοΈ Limiting replies to particular senders
- β³ π¨ Telling the analyst a ticket is theirs
- β³ βοΈ Email signatures
- β³ π The public web address
- β³ π’ Ticket numbering
- β³ π Raising a ticket for someone else
- β³ π Merging tickets
- β³ π Confidential tickets
- β³ π₯ Portal managers
- β³ π Who has seen a ticket
- β³ π Reading long tickets
- β³ β Splitting tickets
- β³ β Selecting several tickets
- β³ ποΈ The folder pane
- β³ π½ Just my tickets, or no closed ones
- β³ π οΈ Snoozing tickets β Developer Guide
- β³ π₯ Collision detection
- β³ β±οΈ Time tracking
- β³ π Scheduled work in your own calendar
- Problem Management
- Tasks
-
Assets
- β³ π’ Moving an asset between companies
- β³ π Shared asset locations
- β³ π§βπΌ Assigning assets to analysts
- β³ π Warranty and lease alerts
- β³ π Saved table views
- β³ π¨οΈ Recording anything, and importing it
- β³ π·οΈ QR asset labels
- β³ π Who holds what, and handover documents
- β³ π₯οΈ The inventory agent (PowerShell)
- β³ ποΈ Proxmox VE servers
- β³ βοΈ VMware Cloud Director servers
- β³ π Linking equipment to tickets
- β³ βοΈ Follow-up tasks on a ticket
- Knowledge
- Change Management
- Calendar
- Morning Checks
- Reporting
- Software
-
Forms
- β³ π¨ The form designer β Developer Guide
- β³ π Layout & the grid β Developer Guide
- β³ ποΈ Collections β grouping submissions
- β³ π Submissions as PDFs
- β³ β‘ What happens next β a form's own actions
- β³ π οΈ Sections & conditional logic β Developer Guide
- β³ π οΈ Lookup fields β Developer Guide
- β³ π‘οΈ Catalogue request approvals
- People
- Domains
- Contracts
- Service Status
- π Notifications
- π¨ War Room
- Self-Service Portal
- LMS
- Process Mapper
- CMDB
- Network Mapper
- Workflows
- Issue trackers (Jira, Azure DevOps)
- System
-
Overview
- β³ π Progress tracker
- β³ Concepts & vocabulary
- β³ Email routing & mailboxes
- β³ Settings: global vs per-company
- β³ Users & self-service
- β³ Staff cross-company access
- β³ π’ One board across every company
- β³ Worked examples
- β³ Pitfalls & gotchas
- β³ Scope: what it's for
- β³ π οΈ Developer Guide (make a module multi-company)
- β³ ποΈ Case study: CMDB (a linked graph)
- β³ π§ͺ Test harness (prove it's isolated)
- What this is
-
π Bugs resolved
- β³ π’ Chat tickets ignored your ticket numbering
- β³ π Dates shown as a dash, or in server time
- β³ π Assets β Users showed people from other companies
- β³ π Restricted analysts could read other modules' data
- β³ πΌοΈ Replies with a picture in the thread failed to send
- β³ π Reply attachments never reached the customer
- β³ π οΈ Outbound email attachments β Developer Guide
- β³ π A global SSO provider was missing from the portal
- β³ π Behind a proxy, the SSO redirect said http
- β³ βοΈ The portal tagline moved when you saved it
- β³ π¨ The portal settings screen forgot what you saved
- β³ π‘οΈ The approvals inbox said "Error" and nothing else
- β³ π A table's answers were missing from the PDF
- β³ β A single-select column let you tick every option
- β³ π The portal ignored a form's field widths
- β³ π The tasks board stopped taking clicks
- β³ ποΈ #121 The index list is out of date after upgrading
- β³ π #133 The calendar subscription was empty
- β³ π #131 Tasks always reopened on the board
- β³ π₯ #129 Every page returned HTTP 500 after upgrading
- β³ π³ #127 A PHP warning above the System page
- β³ π #126 Notes stamped with the server's clock
- β³ π Storing every date in UTC
- β³ πͺ The portal was down for everyone signed in
- β³ βοΈ #120 Workflow notes could never be written
- β³ βοΈ #123 Three errors when running Database Verification
- β³ π #122 The description box was a stub in the corner
- β³ π£ Demo data deleted real accounts
- β³ π #117 Sign-in redirected to the wrong address
- β³ π¨ #108 The priority dot was invisible
- β³ β±οΈ #116 Time logged from the right-click menu
- β³ π #114 API keys refused by our own guard
- β³ ποΈ #110 Assigning a task told nobody
- β³ πͺ #107 Signed out while still working
- β³ π #103 "Share with Requester" reached nobody
- β³ π #102 Search found nothing for hyphens
- β³ πͺ #101 Source code editor opened behind
- β³ βοΈ #88 Subtasks could not be ticked off
- β³ π» #84 Asset deep link selected nothing
- β³ π« #79 A new ticket arrived with no status
- β³ π§ #79 A ticket from email did not say so
- β³ π #78 Bell opened to nothing
- β³ π¬ #77 Mail only collected from Inbox
- β³ π #74 The default password could not be changed
- β³ π¦ #70 Renaming an impact level
- β³ π€ #67 App-only mailboxes could not send
- β³ π #45 Verify only ever worked for Microsoft
- β³ π #45 IMAP reported as not authenticated
- β³ βοΈ An email template stopped escaping itself
- β³ π The portal dashboard showed the wrong time
- β³ π’ The folder said 99 and the list showed 96