This article summarizes the permissions available to each Case Management role.
Users can hold more than one role. When multiple roles are assigned, the user's effective permissions are the combination of all assigned roles.
For guidance on choosing roles, see Roles and permissions.
Role summary
| Role | Typical responsibilities |
| Case Administrator | Configure Case Management, manage access, and oversee the entire solution. |
| Case Manager | Manage one or more HR service teams, assign work, and oversee queues. |
| Case Agent | Resolve employee requests and manage assigned cases. |
| Case Audit | Review cases and history for compliance or quality assurance. |
| Case Collaborator | Participate in specific cases when invited. |
| Employee | Raise requests and track their own cases. |
Permissions by role
| Capability | Case Administrator | Case Manager | Case Agent | Case Audit | Collaborator | Employee |
| View own cases | ✓ | ✓* | ✓* | ✓* | ✓* | ✓ |
| View assigned cases | ✓ | ✓ | ✓ | ✓ | Invited only | — |
| View all cases in managed teams | ✓ | ✓ | — | ✓ | — | — |
| View every case in the organization | ✓ | — | — | ✓ | — | — |
| View canceled cases | ✓ | Team only | — | ✓ | — | — |
| Create cases on behalf of employees | ✓ | ✓ | ✓ | — | — | — |
| Reply to employees | ✓ | ✓ | ✓ | Contributor only | — | |
| Add internal notes | ✓ | ✓ | ✓ | — | — | — |
| Use Ask AI | ✓ | ✓ | ✓ | — | — | — |
| Update case status | ✓ |
✓ | ✓ | — | — | — |
| Update categories, flags, and priority | ✓ | ✓ | ✓ (assigned cases) | — | — | — |
| Change assignee | ✓ | ✓ | — | — | — | — |
| Change team | ✓ | ✓ | — | — | — | — |
| Complete manual triage | ✓ | ✓ | — | — | — | — |
| Claim unassigned cases | ✓ | Assigns instead | ✓ | — | — | — |
| Bulk update cases | ✓ | ✓ (managed teams) | — | — | — | — |
| Merge duplicate cases | ✓ | ✓ (managed teams) | ✓ (accessible cases) | — | — | — |
| Reopen cases | ✓ | ✓ (managed teams) | — | — | — | Request by replying during grace period |
| Force-close cases | ✓ | ✓ (managed teams) | — | — | — | — |
| Cancel cases | ✓ | ✓ (managed teams) | — | — | — | Requester only (within organization rules) |
| Delete or redact public updates | ✓ | ✓ (managed teams) | — | — | — | — |
| Override experience metrics | ✓ | ✓ (managed teams) | — | — | — | — |
| Open Case Setup | ✓ | — | — | — | — | — |
| Configure teams, SLAs, notifications, and lifecycle | ✓ | — | — | — | — | — |
| Create personal views | ✓ | ✓ | ✓ | ✓ | ✓ | — |
| Create team-scoped shared views | ✓ | ✓ | — | — | — | — |
| Create organization-wide views | ✓ | — | — | — | — | — |
* Users can always access their own employee cases through the employee portal.
Team-based permissions
Some permissions depend on team membership.
Case Managers
Case Managers can:
- View every case belonging to the teams they manage.
- Assign and reassign work.
- Complete manual triage.
- Reopen, force-close, or cancel team cases.
- Override experience metrics for team cases.
- Create team-scoped shared views.
These permissions don't apply to cases outside their managed teams.
Case Agents
Case Agents can:
- Work assigned cases.
- Claim AI-triaged unassigned cases for their teams.
- Update classification on assigned cases.
- Create cases on behalf of employees.
Agents can't claim cases until automatic triage has completed and the case belongs to one of their teams.
Collaborator permissions
Collaborators receive access only to the cases they've been invited to.
| Collaborator type | Capabilities |
| Viewer | View the case only. |
| Contributor | View the case and send public updates. |
Collaborators can't change routing, assignments, priorities, or other case classifications.
Employee access
Employees don't require a Case Management role.
Employees can:
- Raise new requests.
- Track their own cases.
- Reply to public updates.
- Complete close surveys.
- Cancel cases they created, subject to your organization's policies.
Employees can't view:
- Internal notes.
- AI activity.
- Routing or classification.
- Service-level information.
Employees added as CCs have read-only access to the case and can't reply or make changes.
Multiple roles
Users can hold more than one role.
For example:
| Assigned roles | Effective access |
| Employee + Case Agent | Resolve cases while continuing to raise and track personal requests. |
| Case Agent + Case Manager | Work assigned cases and manage team workloads. |
| Case Manager + Case Administrator | Manage teams and configure Case Management. |
| Case Administrator + Case Audit | Configure the system while retaining read-only audit visibility. |