Summary: ◀▼
Full end-user separation isolates customer data by brand, creating separate user records, tickets, and histories for each brand. This supports privacy, regulatory compliance, and limits agent access to relevant brands. It suits companies needing strict data separation between departments or regions but has limitations like unsupported channels and no ticket brand changes. Testing workflows before production use is recommended.
Full end-user separation isolates end-user data by brand. It's designed for companies who need stronger separation between departments, regions, or business units that share one account but should not share customer records.
With full end-user separation, each separated brand has its own end-user directory. The same person can have a different user record in each separated brand, with separate tickets, user fields, and history. This helps companies support stricter privacy, regulatory, and operational requirements.
Understanding full end-user separation
Full end-user separation is part of the department spaces feature. It fully isolates end-user data between brands that are configured as separated brands.
In a standard multi-brand account, end-user records can be shared across brands. With full end-user separation, a separated brand keeps its own directory of end users. If the same person interacts with multiple separated brands, Zendesk creates a separate user record for each brand instead of sharing one record across the account.
This model helps solve common problems for larger companies, including:
- Preventing end-user data from being visible across departments when it should be isolated
- Supporting different customer data sets for different brands
- Meeting geographic, regulatory, or internal policy requirements for data separation
- Limiting agent access to only the end-user profiles associated with the brands they work in
For example, one customer might contact two brands in the same account using the same email address. With full end-user separation, that person can exist as two separate end-user records, one in each separated brand, without identity conflicts.
Reviewing how separated brands work
A separated brand is a brand that is created with full end-user separation enabled. When a brand is separated, end-user data created in that brand is isolated from other brands. Brands that are not separated continue to work as they do today and continue sharing end-user data with each other.
Full end-user separation includes the following behavior:
- End-users created in a separated brand are visible only in that brand.
- The same person can have separate user profiles in different brands.
- Each profile has its own tickets, fields, and history.
- Email addresses, phone numbers, and external IDs can be reused across separated brands.
- Identity matching happens within the brand, not across the entire account.
- Help center authentication is scoped to the brand, so end users sign in separately for different separated brands.
- End users in separated brands can only be accessed by agents assigned to those brands.
Separated end users are also limited to interactions within their own brand. An end user in a separated brand can only be a requester, CC, or participant on tickets in that same brand.
Organizations are not separated by brand. Organizations remain outside of brands, and both brand-scoped and global users can belong to any organization.
Considering EAP limitations and eligibility
This EAP is a first release and has important limitations. Because this is a closed EAP, participation is also subject to Zendesk eligibility criteria.
Brand requirements
- Full separation can be enabled only on new brands.
- Existing brands are not supported in this release.
- After a brand is created as separated, you cannot turn separation off.
- After a user is assigned to a department or separated brand, that user cannot be reassigned to another department or brand.
Zendesk plans to support existing brands in a later release.
Unsupported channels
The following channels aren't supported in this EAP:
- Voice
- Contact Center
- Talk Partner Edition
- X Corp public posts
- Public Facebook messaging
- Channels Framework API integrations
The following related channels are supported:
- X Corp direct messages using messaging
- Facebook Messenger using messaging
Ticketing limitations
- You can't change the brand on a ticket that belongs to a separated brand.
- You can't move a ticket into a separated brand after the ticket is created.
- Triggers or automations that try to change the brand on a ticket in a separated brand will not make the change.
- You can't merge tickets across brands if either brand is separated.
- Tickets can be merged only within the same brand.
- Agents can't add CCs or followers who don't have access to the ticket's brand.
User and agent limitations
- End users in a separated brand can be merged only with other end users in that same brand.
- Agents who have interacted with more than one brand can't be downgraded to a customer.
- Customers who have interacted with more than one brand can't be upgraded to an agent.
Deciding whether to participate in the EAP
Full end-user separation may be a good fit if your company needs to isolate customer data between brands while still managing those brands in one account.
You may want to participate if you need to:
- Keep customer records separate between departments or business units.
- Support different user profiles for the same person in different brands.
- Reuse the same email address, phone number, or external ID in different brands.
- Restrict agent visibility so agents see only the end users in the brands they can access.
- Better align Zendesk with your internal data model.
- Support privacy or regulatory requirements that require stronger separation of customer data.
This EAP may not be a good fit if you need to:
- Apply separation to existing brands immediately.
- Use unsupported channels such as Voice or Contact Center.
- Move tickets between brands after they are created.
- Maintain cross-brand workflows that depend on shared end-user records.
If you are evaluating the EAP, review your current brand structure, channels, automations, and ticket routing rules carefully. In particular, check whether any existing workflows depend on changing ticket brands or sharing end-user identities across brands.
Getting started with the EAP
If your company is interested in the EAP, complete the sign-up form.
If you're approved for the EAP, the basic setup flow is:
- Request to participate in the EAP, then wait for confirmation that the EAP has been enabled on your account.
- In Admin Center, create a brand with full separation enabled.
- Add team members to the brand so they can access its tickets and end users.
- Test your workflows in a sandbox before using the feature in production.
Testing is strongly recommended because separation affects identity matching, authentication, ticket participation, and brand-based visibility.