How to Configure Roles and Permissions in ManageEngine ServiceDesk Plus - Solution for Guru

Skip to main content
Table of Contents
< All Topics
Print

How to Configure Roles and Permissions in ManageEngine ServiceDesk Plus

Quick Summary

Every help desk faces the same underlying question: who should see which tickets, and who should be allowed to act on them. ServiceDesk Plus answers this through a role-based access system that lets administrators define exactly what each technician can view, edit, or approve across the application. This guide walks through how that system works and how to configure it correctly for your organization.

Since roles and permissions form the backbone of how a service desk actually runs day to day, it helps to understand the platform they belong to first. ManageEngine ServiceDesk Plus – ITSM Software provides the ticketing, asset management, and workflow tools that these permissions ultimately control access to, and it offers useful context before diving into the configuration steps covered in this article. With that framing in place, let’s look at how roles and permissions actually work in ServiceDesk Plus.


What Are Roles and Permissions in ServiceDesk Plus?


ManageEngine ServiceDesk Plus

How does ServiceDesk Plus separate users from technicians?

ServiceDesk Plus splits accounts into two distinct categories, and this distinction shapes everything about how permissions work. Requesters, typically regular employees, can raise and view their own tickets, but the application does not let administrators customize their access beyond a small set of predefined options. Technicians, on the other hand, receive specific roles that determine what modules and actions they can access across the entire application, which makes role configuration a technician-focused exercise rather than something applied broadly to every account. Understanding this split early prevents a common early mistake, where an administrator spends time trying to fine-tune requester permissions that the application simply doesn’t expose for customization.

What exactly does a “role” control?

A role in ServiceDesk Plus defines the level of access a technician holds over the application, broken down by module. Administrators can assign multiple technicians to the same role, and the Role List View page lets you see exactly which technicians currently hold a given role, so auditing who has access to what doesn’t require digging through individual accounts one by one.

How granular can permission settings actually get?

Permission configuration goes well beyond a simple “can view” or “cannot view” toggle. Administrators can set access permissions across modules and then fine-tune what a technician can do within each one using action-level permissions, such as editing a ticket versus only viewing it. Access can also be restricted further by site, group, or specifically to tickets assigned to that technician, which keeps large service desks organized as they scale.


Where Do You Configure Roles in the Dashboard?

How do you access the Roles Configuration page?

Reaching the roles configuration screen takes just a couple of clicks from the Admin section:

  1. Log in to ServiceDesk Plus with an administrator account.
  2. Click the Admin tab in the header.
  3. Navigate to Users & Permissions, then select Roles.
  4. Review the Role List View page to see existing roles and their assigned technicians.

Does the navigation path differ between product editions?

Yes, slightly. The standard ServiceDesk Plus edition and the MSP edition organize the Admin section a bit differently, and older interface versions use a separate path entirely. In the MSP edition, for example, the same page can also be reached through Admin > MSP Details > Roles on the older interface, so it’s worth confirming which UI version your organization is running before following outdated instructions from an older guide.

What should you check before creating a new role?

Before adding a custom role, review the default roles ServiceDesk Plus already provides. In many cases, an existing default role, or a lightly modified version of one, covers what you need without requiring you to build permissions entirely from scratch. This default-first approach also reduces the chance of accidentally leaving a permission gap that a more thoroughly tested default role wouldn’t have.


How Do You Create a Custom Role?

What information do you need to define a new role?

Once you’ve decided a custom role is necessary, the Roles Configuration Wizard walks through the required details. You give the role a clear, descriptive name and a brief explanation of its intended purpose, which matters more than it might seem, since a well-labeled role saves considerable confusion later when auditing access across a growing technician list.

How do you assign specific permissions to the role?

Permission assignment happens on a per-module basis, and the table below summarizes the general structure most roles follow.

Configuration AreaWhat You Define
Module accessWhich modules the role can view, such as Requests, Assets, or Changes
Action-level permissionsWhether the technician can create, edit, close, or only view records
Scope restrictionsWhether access applies fleet-wide or limited by site, group, or assignment
Approval permissionsWhether the technician can approve requests, purchase orders, or changes

Can a role apply to more than just standard technicians?

Yes. ServiceDesk Plus lets administrators decide whether a role applies broadly to all users or only to technicians, which becomes particularly relevant for specialized processes like change management. Change roles, for example, ask the administrator to specify whether the role applies to all users or technicians only, giving flexibility for organizations that involve non-technician stakeholders, such as business approvers, in specific workflows.


How Do You Assign Roles Once They’re Created?

How do you assign a role to a technician?

Assigning a role happens either during technician creation or afterward through the technician’s profile settings. Administrators can add technicians in a couple of different ways, including converting an existing requester into a technician directly from the Requesters section, then assigning the appropriate role as part of that conversion.

Can technicians be tied to specific sites or groups during assignment?

Yes, and this step matters for keeping large or multi-location service desks organized. While assigning a technician’s role, you can also associate them with one or more specific sites and groups, which determines which tickets they can actually see and act on. A common configuration example involves setting a technician’s view permissions so they can only see requests from their own group, meaning a technician assigned to HR won’t see tickets raised for a completely different department, like Facilities.

Can roles be assigned to entire groups instead of individual technicians?

Yes. Rather than assigning a role to each technician one at a time, ServiceDesk Plus supports assigning roles to groups directly, which streamlines configuration considerably for larger service desks. This group-based approach also extends across multiple service desk instances, so organizations running separate desks for departments like HR or Facilities can apply a consistent access model without duplicating the setup process for every team. As a service desk grows and onboards new technicians regularly, group-based assignment also reduces ongoing administrative overhead, since a new hire added to an existing group automatically inherits the correct permission set without requiring a separate manual configuration step for each individual account.


What Should You Know About Advanced Permission Scenarios?

How does approval authority get configured separately from general permissions?

Approval permissions work as a distinct layer on top of general role access, since not every technician who can view or edit a ticket should also be able to approve it. Administrators can configure whether a technician acts as a Service Request Approver or a Purchase Order Approver independently from their standard role assignment, which keeps approval authority tightly controlled even among technicians who otherwise share the same general permissions.

How do change management roles differ from standard technician roles?

Change roles follow a more specialized configuration path, since changes typically move through multiple review stages before implementation. When setting up a change role, an administrator configures access permissions across each individual change stage separately, for example granting approval rights during the Submission and Review stages specifically, rather than applying one blanket permission across the entire change lifecycle. This stage-by-stage control reflects how change management naturally works, since different reviewers often need authority at different points in the process.

Can access controls extend down to individual asset or CMDB fields?

Yes, for organizations that need that level of precision. ServiceDesk Plus supports attribute-level access controls for sensitive asset and CMDB data, letting administrators lock down specific fields rather than restricting access at the record level alone. This granularity matters for organizations handling sensitive infrastructure details that shouldn’t be visible to every technician who otherwise has general asset module access. A financial services company, for example, might allow every technician on the asset team to view general hardware inventory, while restricting visibility into fields that reveal network topology or security configuration details to a smaller, more senior subset of that same team.


Conclusions

Configuring roles and permissions in ServiceDesk Plus comes down to matching each technician’s actual responsibilities to a precisely scoped set of module, action, and approval permissions. Starting from the built-in default roles, then layering in custom roles, site and group restrictions, and stage-specific change permissions as your service desk grows, keeps access control both manageable and secure. Reviewing existing role assignments periodically, rather than only at initial setup, also helps catch permission creep before it becomes a larger cleanup project down the line. For a fuller picture of how these permissions connect to the platform’s broader ticketing, asset, and workflow features, ManageEngine ServiceDesk Plus – ITSM Software remains a valuable resource alongside the configuration steps covered in this guide.


Frequently Asked Questions

Can I customize the permissions available to requesters, not just technicians?

No. ServiceDesk Plus pre-defines requester roles, and administrators cannot configure custom permissions for that account type. Custom role configuration applies specifically to technicians, who can then be granted module access, action-level permissions, and approval rights based on their responsibilities.

What happens if I assign a technician to multiple groups with different role permissions?

The technician’s actual access reflects the combination of every role and group assignment tied to their account, so it’s worth reviewing assignments carefully to avoid unintentionally granting broader access than intended. Checking the Role List View page periodically helps confirm which technicians hold which roles across your organization.

Do I need separate roles for change management, or can I reuse standard technician roles?

Change management typically calls for dedicated change roles rather than reused standard roles, since changes move through distinct stages like submission, review, and implementation that each require their own access configuration. Setting up dedicated change roles gives you stage-specific control that a general technician role doesn’t provide.


Recommended: