Zendesk Workforce management (WFM) roles and permissions ensure that agents and admins have access to the WFM features they need to use.

What's my plan?
Add-on Workforce Management (WFM) or Workforce Engagement Management (WEM)

Verified AI summary ◀▼

Understand workforce management roles and permissions to control access to features and data. Use standard roles like Admin and Agent or create custom roles to match your organization’s structure. Assign permissions for tasks like scheduling, reporting, and time-off management, and define scopes to limit access to specific teams and locations. This setup ensures users have the necessary access without overexposure.

Zendesk Workforce management (WFM) roles and permissions ensure that agents and admins have access to the WFM features they need to use.

Your account includes standard, predefined roles that all Zendesk users are initially assigned to. You can also create your own custom WFM roles to reflect your organization's structure and access management system.

This article contains the following topics:

  • Overview of WFM roles and permissions
  • Standard WFM roles
  • Custom WFM roles
  • WFM permissions

Related articles

  • Creating custom WFM roles and assigning users
  • Managing WFM roles and permissions

Overview of WFM roles and permissions

WFM roles and permissions allow you to manage who can do what in your account. They help your organization run smoothly by making sure everyone has the access they need.

There are two kinds of roles:
  • Standard roles are predefined and can’t be deleted. All users in your Zendesk account are initially assigned a standard role depending on their Zendesk role.
  • Custom roles are defined by admins who determine which parts of your WFM account users in these roles can access. This includes which teams, locations, and workstreams they can see.

When you assign someone to a role, they inherit the permissions and scopes associated with that role. Note that users can be assigned only one role at a time.

Both standard and custom roles have the same structure, which include:

  • Permissions – Allows users to access certain areas of your WFM account, such as scheduling, reporting, or admin settings. Permissions keep your account secure and ensure that users have access only to what they need.
  • Scopes – Determines the teams, locations, and workstreams that users have access to in their role. Setting a role’s scope lets admins give users permission for certain features without sharing information about all teams, locations, and workstreams.
    Note: Agents who aren’t assigned to a team are visible to all roles. Be cautious when you assign an unassigned agent to a team, because this can expand visibility instead of restricting it. Roles with matching team-based scopes then also gain the same visibility as that agent.
  • Agents – The users assigned to the role.

Standard WFM roles

Your WFM account has two standard, predefined roles: Admin and Agent. By default, Zendesk admins are automatically assigned to the WFM admin role. The rest of your Zendesk team members are assigned to the WFM agent role.

In addition to the standard roles, you can create custom roles that reflect your organization’s structure and reassign users to those roles.

Admin role

The standard WFM admin role can’t be edited, except to be renamed, or deleted.

WFM admins have permissions for all features, can manage which users are assigned to each role, and their scope includes access to information about all teams, locations, and workstreams.

Your account must always have at least one user assigned to the default WFM admin role. For example, you may want your system administrator to be assigned to this role so that they have full access to all features and resources in the system.

Agent role

The standard WFM agent role can’t be deleted.

By default, the standard WFM agent role gives agents permission to access only the Schedule in Zendesk Support. Admins can edit this role to give access to more features, though.

The scope for users assigned to the standard WFM agent role includes access to information about their own teams, locations, and workstreams.

Custom WFM roles

Custom WFM roles are roles admins create that reflect your organization’s structure. Create custom roles to allow or restrict access and specify different permissions for your agents, team leads, admins, managers, or other roles.

Common examples of roles you may want to create include:
  • Manager
  • Supervisor
  • Team lead
See Creating custom WFM roles and assigning users.

WFM permissions

WFM permissions are configured for each role. By configuring permissions for a role, you’re defining whether users assigned to a role have access to certain WFM features.

You can grant a role no access, view and manage access, or custom permissions for each feature.
Note: When you configure permissions for a role, keep in mind that they're limited to the role’s scope.

WFM permissions are segmented by feature area as follows:

Permissions Description
Monitoring
  • View and manage: Can view, export, create, edit, and delete dashboards, agent activity, agent attendance, agent status, and performance boards.
  • Custom permissions

    Dashboards

  • View and manage: Can view, create, edit, and delete dashboards.
  • Custom permissions

    Agent activity

  • View and manage: Can view, create, export, edit, and delete activities.
  • Custom permissions

    Agent attendance

  • View only: Can view the agent attendance page.
  • Custom permissions

    Agent status

  • View only: Can view the agent status page.
  • Custom permissions

    Performance boards

  • View and manage: Can view, create, edit, and delete performance boards.
Reporting
  • View and manage: Can view, export, schedule, create, edit, and delete custom reports, system reports, and scheduled reports.
  • Custom permissions

    Custom reports

  • View and manage: Can view, edit, create, export, and delete custom reports.
  • Custom permissions

    System reports

  • View and manage: Can view, edit, duplicate, create, export, and delete system reports.
  • Custom permissions

    Scheduled reports

  • View and manage: Can view, create, edit, and delete scheduled reports.
Forecasting
  • View and manage: Can view, export, create, edit, and delete forecast and Forecast vs actual (EAP).
  • Custom permissions

    Forecast

  • View and manage: Can view, create, edit, export, and delete forecasts.
  • Custom permissions

    Forecast vs actual

  • View only: Can view the forecast vs actuals page (EAP).
Scheduling
  • View and manage: Can view, export, generate, publish, add, edit, and delete schedules, time offs, shift trades, and unassigned shifts.
  • Custom permissions

    Schedule

  • View and manage: Can view, create, edit, import, export, generate, publish, and delete schedules.
  • Custom permissions

    Time off management

  • View and manage: Can view, create, edit, approve, deny, respond to, reopen, and delete time off requests.
  • Custom permissions

    Trades management

  • View and manage: Can manage and view pending and closed shift trade requests.
  • Custom permissions

    Unassigned shifts management

  • View and manage: Can manage and view pending and closed unassigned shifts.
People
  • View and manage: Can view, export, sync, create, edit, and delete teams.
  • Custom permissions

    Teams

  • View only: Can view teams.
  • View and manage: Can view, create, edit, sync, export, and delete teams.
Settings
  • View and manage: Can view, create, edit, and delete locations, workstreams, time off reasons, automations, integrations (the Google calendar and the Workday integrations), account settings, and general tasks.
  • Custom permissions

    Locations

  • View and manage: Can view and manage locations.
  • Custom permissions

    Workstreams

  • View and manage: Can view and manage workstreams.
  • Custom permissions

    Time off reasons

  • View and manage: Can view and manage time off reasons.
  • Custom permissions

    Automations

  • View and manage: Can view and manage automations.
  • Custom permissions

    Integrations

  • View and manage: Can view and manage the Google calendar integration and the Workday integration (EAP) by changing their parameters, including turning them on and off.
  • Custom permissions

    Settings

  • View and manage: Can view and manage account settings.
  • Custom permissions

    General tasks

  • View and manage: Can view and manage general tasks.
Agent
  • View and manage: Can view, create, and delete the agent schedule, time off, trades, and unassigned shifts.
  • Custom permissions

    Agent schedule

  • View and manage: Can view the agent schedule.
  • Custom permissions

    Time off

  • View and manage: Can view and manage time offs.
  • Custom permissions

    Trades

  • View and manage: Can view and manage shift trade requests when shift trading has been activated for the account.
  • Custom permissions

    Agent unassigned shifts

  • View and manage: Can view and manage agent unassigned shifts.
Powered by Zendesk