-
-
Notifications
You must be signed in to change notification settings - Fork 27
Portal Managers
Added in 2.8.0 Β· Asked for in discussion #62 Β· Developer guide
A manager is someone in the self-service portal who can see the tickets raised by the people they manage. The head of Logistics sees Logistics' tickets: the new starter still waiting on a laptop, the fault that has stopped the whole team, the ticket still open when somebody leaves.
A manager gets a Team tickets tab in the portal, next to My Tickets. The service desk is not affected: who on the desk sees what is still decided by teams, departments and companies.
Off until you switch it on, under System β Managers. It also stays off, whatever is set, until System β Database Verification has run. Nothing about it changes what anybody sees until then.
Two sources, used together:
| Source | Set where | Good for |
|---|---|---|
| The Manager field | On each person's record, by hand or from your directory (Active Directory's manager). System β Managers turns it on or off, and chooses direct reports only or everyone below them. | Line managers, with no extra work if your directory already knows the reporting line |
| Management lines | The Manager access page for that person | A head of department, a site lead, a deputy covering someone's team - anyone the reporting line doesn't capture |
A management line gives a manager one of:
- everyone in their company;
- a person;
- a people group - the same groups Knowledge and Training use, with the same rules, so an expired membership stops counting;
- a department, by name;
- their reporting line - direct reports or everyone below them - for this one manager, even when the Manager field isn't used for everybody.
An exclusion leaves out a person, a group or a department. An exclusion always wins, over every line and over the Manager field. "Everyone in Sales except the person who has raised a grievance about me" is exactly what it's for.
Somebody can have two managers. A manager can have any number of lines.
Open a person on Tickets β Users or Assets β Users and press Manager access beside Edit. Or click a manager's name on System β Managers.
It's a full page rather than a pop-up on purpose. On a large organisation there are thousands of people and hundreds of departments, and everything on it is searched a page at a time.
At the top: how many people the Manager field alone gives them, and how many people's tickets they can see in all. Below, three full-height panels, left to right, each with tabs and a search box at the same height, and each scrolling on its own so nothing jumps about as you work:
- Add to their team: tabs for People, Groups, Departments and Everyone (which also holds their reporting line). Search, then Add or Exclude. Only people in the manager's own company are ever offered, and every department shows how many people it would bring in. The list stays where you scrolled it; what you added is simply marked Added.
- What gives them access: their management lines, in tabs - People (n), Groups (n), Departments (n), and Everyone when they have one - alphabetical, with that tab's exclusions beneath. Each shows how many people it covers and who added it when, and a department nobody is in any more is flagged - has it been renamed? It follows the tab you pick on the left, and shows whatever you just added.
- Who they can see: the list itself, which you can filter. Click anyone to see why: a picture of the manager branching through each reason - the Manager field (with anyone in between), a department, a group, named, everyone, the reporting line - to that person, what the manager can do with their tickets, and a numbered way to stop each reason. Exclude is always the last, since it beats them all; you can remove a line or exclude them right there, and the explanation updates.
Somebody who can only look, not change, gets panels 2 and 3. On a narrow screen the panels stack.
Everything on it is worked out as if managers were already switched on, so you can set people up and check the result before the portal changes.
Who may change lines is a System β Managers setting: administrators only (the default), or anyone who can edit people. Everyone else sees the page read-only, with a note saying so.
- Same company only. A manager only ever sees people, and tickets, in their own company. If you've never set up companies, everybody is in the Default company and there's nothing to do.
- A manager who has left sees nothing. Their lines are kept in case they come back.
- Their own tickets stay under My Tickets, never in the team.
- People who have left: managers keep seeing their tickets by default, because an open ticket still needs oversight after its requester goes. System β Managers can turn that off.
- Departments are matched on the name typed on each person, ignoring capitals and spaces at either end. Rename a department and a line for the old name stops matching - which is why both screens warn about it.
The list shows the newest 50 first, with Load more at the bottom for the next 50. Above it, pick a person, a status, or both - each with a count, and worked out across all of the team's tickets, not just the ones loaded.
Every manager has a notification bell in the portal header - the same bell analysts have. It belongs to being a manager: the settings decide what is sent to it (new team tickets today, other things later), not whether it is there.
System β Managers β Telling managers about new tickets - one of:
| Setting | What happens |
|---|---|
| Don't notify (default) | Nothing. Managers see new tickets when they look at Team tickets. |
| Email them | An email with the ticket's number and subject and a link to it, to the manager's address, from the ticket mailbox. Managers with no address get nothing. |
| In the portal's notification bell | Into the bell every manager has in the portal header - the same bell analysts have. Quieter than email: it is there when they next sign in. |
Never for a ticket the manager may not open - so never for a confidential ticket, whatever the confidential setting, and never for a ticket that arrived through a confidential mailbox: it is confidential before anybody is told.
Tickets raised through web chat, WhatsApp or the request catalogue are not announced - the same gap the analysts' bell has.
A manager can always read a team ticket. System β Managers decides whether they can also reply to it or close it (both off by default). Each team ticket carries a banner saying whose it is and what the manager may do.
A reply goes out under the manager's own name, and a close is recorded as Closed by manager.
What a manager sees of a confidential ticket:
| Setting | The manager sees |
|---|---|
| Nothing at all (default) | Nothing. They can't tell it exists. |
| That it exists | "Confidential ticket", with its number and status and nothing it says. Even this can tell a manager that someone raised something private. |
| Everything | The ticket, like any other. Only for a portal where nothing confidential is ever raised. |
Opening a team ticket is recorded. The person who raised it sees Who has seen this ticket, with the manager's name and when they last looked. Not when all the manager could see was a confidential stub - they saw nothing of what it says, so nothing is recorded. See Who has seen a ticket.
The settings above, and a list of every manager: anyone with a management line, plus - while the Manager field is used - anyone who is somebody's manager. It's searched and shown a page at a time. For each manager it shows where their access comes from, how many people they can see, and two warnings:
- Has left - sees nothing
- Nobody is in "β¦" - renamed?
- Run Database Verification if the page asks.
- Set up confidentiality first. Mark an HR mailbox or department confidential (Tickets β Settings), so those tickets are protected from the moment managers can look.
- Read the list of managers. A count that looks too high, or a department warning, is worth opening before the switch rather than after.
- Tell your people. The portal tells requesters that confidential tickets are kept from managers, and shows who has looked - but it's kinder to hear it from you first.
- Switch on, and look at the portal as a manager.
Run System β Database Verification once. Until then managers stay off whatever System β Managers says, because a confidential ticket couldn't be told apart.
- Confidential tickets
- Who has seen a ticket
- Contact details - the Manager field and the person editor
- Self-Service Portal
- Portal managers β Developer Guide
FreeITSM β an open-source IT Service Management platform Β· github.com/edmozley/freeitsm Β· MIT licence
- Installation
- β° Scheduled tasks (cron jobs)
- Architecture
- π§ͺ Developer tests
- AI Providers
- Internationalisation (i18n)
- Timezones & Time Handling
- π Date & Time Formats
- Theming & Dark Mode
- ποΈ Recent β getting back to what you were doing
- β¨οΈ Command palette (βK)
- π Searching inside tickets
- π Attached documents
-
MobileβFriendly
- β³ π« Mobile: Tickets
- β³ π» Mobile: Assets
- β³ π Mobile: Calendar
- β³ π Mobile: Knowledge
- β³ π¦ Mobile: Service Status
- β³ πΌ Mobile: Watchtower
- β³ π§© Mobile: Problem Management
- β³ π Mobile: Change Management
- β³ πΏ Mobile: Software
- β³ β Mobile: Tasks
- β³ π Mobile: Forms
- β³ π Mobile: Contracts
- β³ π Mobile: Domains
- β³ π Mobile: People
- β³ π Mobile: LMS
- β³ πΊοΈ Mobile: CMDB
- β³ πΊοΈ Mobile: Network Mapper
- β³ π§ Mobile: Process Mapper
- β³ βοΈ Mobile: Workflow
- β³ π₯οΈ Mobile: System
- β³ π Mobile: Reporting
- β³ π Mobile: System Wiki
- β³ π Mobile: Self-Service Portal
- β³ π§° Mobile: Techniques & Tricks
-
Security
- Layer 1 β which modules you can enter
- β³ π§© Module Access Control
- β³ π οΈ Module Access β Developer Guide
- Layer 2 β what you can administer
- β³ π Roles & Permissions
- β³ π οΈ Roles β Developer Guide
- β³ π€ Why capabilities are constants
- Layer 3 β the System module
- β³ π Admin Access Control
- Hardening
- β³ π Security review response 2026-08
- β³ π‘οΈ Security hardening 2026-08
- β³ π οΈ Security hardening 2026-08 β Developer Guide
- β³ π‘οΈ Round three β plain English
- β³ π οΈ Round three β Developer Guide
- β³ π‘οΈ CSRF protection (S4) β Developer Guide
- Single Sign-On (SSO)
- ποΈ LDAP & Active Directory
- π CardDAV contact sync
- Browser Extension
- API Reference
-
π REST API β how it works
- β³ π« REST API: Tickets
- β³ π» REST API: Assets
- β³ π΄ REST API: Problems
- β³ π REST API: Changes
- β³ π REST API: Knowledge
- β³ β REST API: Tasks
- β³ ποΈ REST API: CMDB
- β³ π REST API: Contracts
- β³ ποΈ REST API: Calendar
- β³ πΏ REST API: Software
- β³ π REST API: Domains
- β³ π¦ REST API: Service Status
- β³ βοΈ REST API: Morning Checks
- β³ π REST API: Forms
- β³ βοΈ REST API: Workflow
- β³ π·οΈ REST API: Cost centres
- β³ πΊοΈ REST API: Network Mapper
- β³ π§ Using the API docs page
- β³ π OpenAPI specification
- β³ β OpenAPI: kept correct
- β³ π οΈ Maintaining the catalogue
- Watchtower
-
Tickets
- β³ π Rota copy and paste β Developer Deep Dive
- β³ β Checklists & SOPs
- β³ βοΈ Mandatory fields
- β³ π·οΈ Ticket categories
- β³ π₯ Assigning tickets to a team, and escalation
- β³ π’ One board across every company
- β³ Mailbox Authentication
- β³ π€ Email send log
- β³ Basic IMAP mailboxes
- β³ Email rendering & images
- β³ SLA Management
- β³ WhatsApp channel
-
β³
βοΈ Telegram channel - β³ β CSAT company scope and filters β Developer Guide
- β³ π₯ Microsoft Teams channel
- β³ π¨οΈ Mattermost channel
- β³ π¬ Web chat channel
- β³ π£ Slack channel
- β³ π Linking tickets
- β³ β Record previews
- β³ π Ticket notes: internal or shared
- β³ ποΈ Canned responses
- β³ βοΈ Limiting replies to particular senders
- β³ π¨ Telling the analyst a ticket is theirs
- β³ βοΈ Email signatures
- β³ π The public web address
- β³ π’ Ticket numbering
- β³ π Raising a ticket for someone else
- β³ π Merging tickets
- β³ π Confidential tickets
- β³ π₯ Portal managers
- β³ π Who has seen a ticket
- β³ π Reading long tickets
- β³ β Splitting tickets
- β³ β Selecting several tickets
- β³ ποΈ The folder pane
- β³ π½ Just my tickets, or no closed ones
- β³ π οΈ Snoozing tickets β Developer Guide
- β³ π₯ Collision detection
- β³ β±οΈ Time tracking
- β³ π Scheduled work in your own calendar
- Problem Management
- Tasks
-
Assets
- β³ π’ Moving an asset between companies
- β³ π Shared asset locations
- β³ π§βπΌ Assigning assets to analysts
- β³ π Warranty and lease alerts
- β³ π Saved table views
- β³ π¨οΈ Recording anything, and importing it
- β³ π·οΈ QR asset labels
- β³ π Who holds what, and handover documents
- β³ π₯οΈ The inventory agent (PowerShell)
- β³ ποΈ Proxmox VE servers
- β³ βοΈ VMware Cloud Director servers
- β³ π Linking equipment to tickets
- β³ βοΈ Follow-up tasks on a ticket
- Knowledge
- Change Management
- Calendar
- Morning Checks
- Reporting
- Software
-
Forms
- β³ π¨ The form designer β Developer Guide
- β³ π Layout & the grid β Developer Guide
- β³ ποΈ Collections β grouping submissions
- β³ π Submissions as PDFs
- β³ β‘ What happens next β a form's own actions
- β³ π οΈ Sections & conditional logic β Developer Guide
- β³ π οΈ Lookup fields β Developer Guide
- β³ π‘οΈ Catalogue request approvals
- People
- Domains
- Contracts
- Service Status
- π Notifications
- π¨ War Room
- Self-Service Portal
- LMS
- Process Mapper
- CMDB
- Network Mapper
- Workflows
- Issue trackers (Jira, Azure DevOps)
- System
-
Overview
- β³ π Progress tracker
- β³ Concepts & vocabulary
- β³ Email routing & mailboxes
- β³ Settings: global vs per-company
- β³ Users & self-service
- β³ Staff cross-company access
- β³ π’ One board across every company
- β³ Worked examples
- β³ Pitfalls & gotchas
- β³ Scope: what it's for
- β³ π οΈ Developer Guide (make a module multi-company)
- β³ ποΈ Case study: CMDB (a linked graph)
- β³ π§ͺ Test harness (prove it's isolated)
- What this is
-
π Bugs resolved
- β³ π’ Chat tickets ignored your ticket numbering
- β³ π Dates shown as a dash, or in server time
- β³ π Assets β Users showed people from other companies
- β³ π Restricted analysts could read other modules' data
- β³ πΌοΈ Replies with a picture in the thread failed to send
- β³ π Reply attachments never reached the customer
- β³ π οΈ Outbound email attachments β Developer Guide
- β³ π A global SSO provider was missing from the portal
- β³ π Behind a proxy, the SSO redirect said http
- β³ βοΈ The portal tagline moved when you saved it
- β³ π¨ The portal settings screen forgot what you saved
- β³ π‘οΈ The approvals inbox said "Error" and nothing else
- β³ π A table's answers were missing from the PDF
- β³ β A single-select column let you tick every option
- β³ π The portal ignored a form's field widths
- β³ π The tasks board stopped taking clicks
- β³ ποΈ #121 The index list is out of date after upgrading
- β³ π #133 The calendar subscription was empty
- β³ π #131 Tasks always reopened on the board
- β³ π₯ #129 Every page returned HTTP 500 after upgrading
- β³ π³ #127 A PHP warning above the System page
- β³ π #126 Notes stamped with the server's clock
- β³ π Storing every date in UTC
- β³ πͺ The portal was down for everyone signed in
- β³ βοΈ #120 Workflow notes could never be written
- β³ βοΈ #123 Three errors when running Database Verification
- β³ π #122 The description box was a stub in the corner
- β³ π£ Demo data deleted real accounts
- β³ π #117 Sign-in redirected to the wrong address
- β³ π¨ #108 The priority dot was invisible
- β³ β±οΈ #116 Time logged from the right-click menu
- β³ π #114 API keys refused by our own guard
- β³ ποΈ #110 Assigning a task told nobody
- β³ πͺ #107 Signed out while still working
- β³ π #103 "Share with Requester" reached nobody
- β³ π #102 Search found nothing for hyphens
- β³ πͺ #101 Source code editor opened behind
- β³ βοΈ #88 Subtasks could not be ticked off
- β³ π» #84 Asset deep link selected nothing
- β³ π« #79 A new ticket arrived with no status
- β³ π§ #79 A ticket from email did not say so
- β³ π #78 Bell opened to nothing
- β³ π¬ #77 Mail only collected from Inbox
- β³ π #74 The default password could not be changed
- β³ π¦ #70 Renaming an impact level
- β³ π€ #67 App-only mailboxes could not send
- β³ π #45 Verify only ever worked for Microsoft
- β³ π #45 IMAP reported as not authenticated
- β³ βοΈ An email template stopped escaping itself
- β³ π The portal dashboard showed the wrong time
- β³ π’ The folder said 99 and the list showed 96