Skip to content

Portal Managers

Ed Mozley edited this page Sep 27, 2026 · 7 revisions

Portal managers

Added in 2.8.0 Β· Asked for in discussion #62 Β· Developer guide

A manager is someone in the self-service portal who can see the tickets raised by the people they manage. The head of Logistics sees Logistics' tickets: the new starter still waiting on a laptop, the fault that has stopped the whole team, the ticket still open when somebody leaves.

A manager gets a Team tickets tab in the portal, next to My Tickets. The service desk is not affected: who on the desk sees what is still decided by teams, departments and companies.

Off until you switch it on, under System β†’ Managers. It also stays off, whatever is set, until System β†’ Database Verification has run. Nothing about it changes what anybody sees until then.


Where managers come from

Two sources, used together:

Source Set where Good for
The Manager field On each person's record, by hand or from your directory (Active Directory's manager). System β†’ Managers turns it on or off, and chooses direct reports only or everyone below them. Line managers, with no extra work if your directory already knows the reporting line
Management lines The Manager access page for that person A head of department, a site lead, a deputy covering someone's team - anyone the reporting line doesn't capture

A management line gives a manager one of:

  • everyone in their company;
  • a person;
  • a people group - the same groups Knowledge and Training use, with the same rules, so an expired membership stops counting;
  • a department, by name;
  • their reporting line - direct reports or everyone below them - for this one manager, even when the Manager field isn't used for everybody.

An exclusion leaves out a person, a group or a department. An exclusion always wins, over every line and over the Manager field. "Everyone in Sales except the person who has raised a grievance about me" is exactly what it's for.

Somebody can have two managers. A manager can have any number of lines.


The Manager access page

Open a person on Tickets β†’ Users or Assets β†’ Users and press Manager access beside Edit. Or click a manager's name on System β†’ Managers.

It's a full page rather than a pop-up on purpose. On a large organisation there are thousands of people and hundreds of departments, and everything on it is searched a page at a time.

At the top: how many people the Manager field alone gives them, and how many people's tickets they can see in all. Below, three full-height panels, left to right, each with tabs and a search box at the same height, and each scrolling on its own so nothing jumps about as you work:

  1. Add to their team: tabs for People, Groups, Departments and Everyone (which also holds their reporting line). Search, then Add or Exclude. Only people in the manager's own company are ever offered, and every department shows how many people it would bring in. The list stays where you scrolled it; what you added is simply marked Added.
  2. What gives them access: their management lines, in tabs - People (n), Groups (n), Departments (n), and Everyone when they have one - alphabetical, with that tab's exclusions beneath. Each shows how many people it covers and who added it when, and a department nobody is in any more is flagged - has it been renamed? It follows the tab you pick on the left, and shows whatever you just added.
  3. Who they can see: the list itself, which you can filter. Click anyone to see why: a picture of the manager branching through each reason - the Manager field (with anyone in between), a department, a group, named, everyone, the reporting line - to that person, what the manager can do with their tickets, and a numbered way to stop each reason. Exclude is always the last, since it beats them all; you can remove a line or exclude them right there, and the explanation updates.

Somebody who can only look, not change, gets panels 2 and 3. On a narrow screen the panels stack.

Everything on it is worked out as if managers were already switched on, so you can set people up and check the result before the portal changes.

Who may change lines is a System β†’ Managers setting: administrators only (the default), or anyone who can edit people. Everyone else sees the page read-only, with a note saying so.


The rules that always apply

  • Same company only. A manager only ever sees people, and tickets, in their own company. If you've never set up companies, everybody is in the Default company and there's nothing to do.
  • A manager who has left sees nothing. Their lines are kept in case they come back.
  • Their own tickets stay under My Tickets, never in the team.
  • People who have left: managers keep seeing their tickets by default, because an open ticket still needs oversight after its requester goes. System β†’ Managers can turn that off.
  • Departments are matched on the name typed on each person, ignoring capitals and spaces at either end. Rename a department and a line for the old name stops matching - which is why both screens warn about it.

Team tickets

The list shows the newest 50 first, with Load more at the bottom for the next 50. Above it, pick a person, a status, or both - each with a count, and worked out across all of the team's tickets, not just the ones loaded.


Telling managers about new tickets

Every manager has a notification bell in the portal header - the same bell analysts have. It belongs to being a manager: the settings decide what is sent to it (new team tickets today, other things later), not whether it is there.

System β†’ Managers β†’ Telling managers about new tickets - one of:

Setting What happens
Don't notify (default) Nothing. Managers see new tickets when they look at Team tickets.
Email them An email with the ticket's number and subject and a link to it, to the manager's address, from the ticket mailbox. Managers with no address get nothing.
In the portal's notification bell Into the bell every manager has in the portal header - the same bell analysts have. Quieter than email: it is there when they next sign in.

Never for a ticket the manager may not open - so never for a confidential ticket, whatever the confidential setting, and never for a ticket that arrived through a confidential mailbox: it is confidential before anybody is told.

⚠️ Emailed links need the public web address (Tickets β†’ Settings β†’ Email Templates, see The public web address). A ticket that arrives by email is created in the background, where FreeITSM cannot tell its own address; without the setting, those emails carry a link that does not work.

Tickets raised through web chat, WhatsApp or the request catalogue are not announced - the same gap the analysts' bell has.


What a manager can do

A manager can always read a team ticket. System β†’ Managers decides whether they can also reply to it or close it (both off by default). Each team ticket carries a banner saying whose it is and what the manager may do.

A reply goes out under the manager's own name, and a close is recorded as Closed by manager.


Confidential tickets

What a manager sees of a confidential ticket:

Setting The manager sees
Nothing at all (default) Nothing. They can't tell it exists.
That it exists "Confidential ticket", with its number and status and nothing it says. Even this can tell a manager that someone raised something private.
Everything The ticket, like any other. Only for a portal where nothing confidential is ever raised.

Being seen

Opening a team ticket is recorded. The person who raised it sees Who has seen this ticket, with the manager's name and when they last looked. Not when all the manager could see was a confidential stub - they saw nothing of what it says, so nothing is recorded. See Who has seen a ticket.


System β†’ Managers

The settings above, and a list of every manager: anyone with a management line, plus - while the Manager field is used - anyone who is somebody's manager. It's searched and shown a page at a time. For each manager it shows where their access comes from, how many people they can see, and two warnings:

  • Has left - sees nothing
  • Nobody is in "…" - renamed?

Before you switch on

  1. Run Database Verification if the page asks.
  2. Set up confidentiality first. Mark an HR mailbox or department confidential (Tickets β†’ Settings), so those tickets are protected from the moment managers can look.
  3. Read the list of managers. A count that looks too high, or a department warning, is worth opening before the switch rather than after.
  4. Tell your people. The portal tells requesters that confidential tickets are kept from managers, and shows who has looked - but it's kinder to hear it from you first.
  5. Switch on, and look at the portal as a manager.

Upgrading

Run System β†’ Database Verification once. Until then managers stay off whatever System β†’ Managers says, because a confidential ticket couldn't be told apart.


See also

FreeITSM

Getting Started

Modules

Multi-tenancy (planned)

Blue sky thinking

Bugs resolved

Links

Clone this wiki locally