Skip to main content
Serval uses a two-level permission system: organization roles control what you can do across the entire org, while team roles control what you can do within specific teams.

Organization Roles

Every user has one organization-level role that applies across all of Serval.
Most users should be Members. Reserve Admin for IT administrators who need to manage the platform. Guests are usually created automatically for external senders from untrusted domains. For more information, see Email intake.
To add a new user, navigate to “Settings” and select “Invite User” —> add their email addresses, choose to make them admin or not and optionally add them to a Serval team

Team Roles

Within each team, users are assigned a team-specific role that controls their capabilities for that team.
A user can be a Manager in one team and an Agent in another. Team roles are independent.
The Drafter role is being rolled out gradually and may not yet be available in your account.

Custom Team Roles

When a built-in role doesn’t have the capabilities you need, create a custom role. A custom role is built on top of a base role and grants additional specific actions. An example of a custom role is a base role of Agent with permission to also view and cancel workflow runs. Custom roles are configured per team, alongside the built-in roles.

Create a Custom Role

  1. Go to Team SettingsRoles. The page lists available built-in roles and any existing custom roles.
  2. Click Create role to open the dialog.
  3. Enter a Name and Description.
  4. Select a Base role. The custom role inherits everything that base role can do. A role without a base role can’t be assigned until you set one.
  5. Under Granted actions, select the extra actions to grant.
  6. Click Create role to save.

The Create a custom role dialog

You can only grant actions that you already hold on the team, so a custom role can’t be used to escalate beyond your own permissions.
The Granted actions list is grouped by area. Campaigns, for example, exposes individual actions to view, create, edit, delete, and archive campaigns. Granting these to a custom role lets you delegate campaign work — such as letting an Agent create and send campaigns — without giving them the full Builder role. A role that can create campaigns can complete the campaign wizard (including selecting recipients and delivery channels) end to end. The Change Management area exposes the change-model, blackout-window, and change-ticket actions, so you can build a scoped “Change Manager” role that authors change models, manages blackout windows, and files changes without granting the full Manager role. The Approvals area exposes the Override approvals action, which lets a role approve or deny the current step of any of the team’s approval requests without being one of its assigned approvers. The override spans tickets, workflow runs, and access requests. Previously reserved for Managers, this break-glass action can now be granted through a custom role without the full Manager role, and every override is recorded in the audit log.

Edit a Custom Role

Open the role from Team SettingsRoles to change its name, description, base role, or granted actions. Select Save after changing the name, description, or base role. Changes under Granted actions are saved separately with Save granted actions, which replaces the complete action selection and confirms with a Granted actions updated message.

Assign a Custom Role

Custom roles are assigned the same way as built-in roles. In the team members list, open a member’s role dropdown. Selecting a custom role sets the member’s base role automatically and attaches the custom permissions. A member holds one direct role grant at a time, but can additionally inherit roles through one or more groups. Changing a member’s direct role doesn’t remove any roles they inherit through groups. Who can manage custom roles:
  • Viewing the Roles page requires View Team Settings.
  • Creating, editing, deleting, and assigning custom roles requires Edit Team Settings, which is typically a Manager.

Permission Summary

What Org Guests Can Do

  • View and reply to the specific tickets they’re associated with
  • Upload attachments to those tickets
  • No access to other tickets, teams, users, or organization settings

What Org Members Can Do

  • Submit tickets through Slack, email, or web portal
  • Request access to applications
  • View their own tickets and access requests
  • Use the catalog to browse access and catalog items

What Org Admins Can Additionally Do

  • Create and manage teams
  • Invite and deactivate users
  • Configure organization settings (SSO, branding, etc.)
  • Access all teams regardless of team membership
  • Manage API keys
  • Share a database with the entire organization (team Managers can share with specific teams, but only an org admin can share org-wide)

What Team Read-Only Agents Can Do

  • View all tickets and journeys associated with their team
  • View team analytics and dashboards
  • View saved views, workbench threads, and the archive
  • Can’t edit tickets, add notes, or change configuration

What Team Agents Can Additionally Do

  • Respond to, update, and resolve tickets
  • Create internal notes
  • Create and edit saved views
  • Retry and cancel workflows while handling tickets
  • View native knowledge base pages

What Team Viewers Can Additionally Do

  • View workflows and skills (read-only)
  • View knowledge sources, databases, and entities (read-only)
  • View access policies, approval procedures, rules, and campaigns (read-only)

What Team Drafters Can Additionally Do

  • Create and edit workflows and skills (can’t run, publish, or delete them)
  • Create and edit native knowledge base pages and tags (can’t delete or archive)

What Team Contributors Can Additionally Do

  • Run published workflows
  • Run workflows on behalf of other team members
  • Can’t publish, delete, or run unpublished workflows
  • Create, edit, and run scheduled Catalyst sessions

What Team Builders Can Additionally Do

  • Create, publish, and delete workflows and skills
  • Run unpublished workflows
  • Install and configure installable workflows
  • Share workflows with other teams
  • Create and edit rules and campaigns
  • Edit knowledge sources
  • Create and edit access policies and approval procedures
  • Create and edit databases and entities
  • Create and edit analytics dashboards

What Team Managers Can Additionally Do

  • Configure integrations and connected apps
  • Manage team settings
  • Manage SLAs, schedules, and visibility groups
  • Run access reviews and override approvals
  • Manage change models
  • View audit logs
  • Archive, trash, and permanently delete tickets

Managing Permissions

Changing Organization Roles

  1. Go to SettingsPeople
  2. Find the user and click their name
  3. Select Member, Admin, or Guest from the organization role dropdown
  4. Save changes

Changing Team Roles

  1. Go to SettingsTeams
  2. Select the team
  3. Find the user in the team members list
  4. Change their role to Read-Only Agent, Agent, Viewer, Contributor, Builder, or Manager (or Drafter, where enabled). Where custom roles exist, the same dropdown also lists them under Custom roles (see Custom Team Roles).
  5. Save changes
Use your identity provider to automatically assign roles. Map directory groups to Serval roles in SettingsIntegrationsDirectory Sync.

Capabilities Toggle

Team managers can enable or disable specific Serval products per team using the capabilities toggle in team settings. This lets you control which features are available to a team — for example, you can disable Access Management for a team that only handles IT support tickets, or enable Workflows only for teams that need automation. Navigate to Team SettingsCapabilities to configure which products are active for each team.

Org Admin Quick Join

Organization admins can add themselves to any Serval team immediately when clicking a ticket link — without navigating to organization settings first. If an admin clicks a link to a ticket in a team they don’t belong to, they can join that team on the spot and access the ticket.

Common Questions

Yes. Organization role and team role are separate. An Org Admin could be an Agent on specific teams if they only need to handle tickets, not configure that team.
Users without team membership can still submit tickets and request access. They just can’t view team visibility groups or use team-specific features.
Access approvers are configured per access policy, not by role. Both Agents and Managers can be designated as approvers.