Understand QCST Component Permissions and Administrator ACL

This article explains core.manage/core.admin plus qcst.manage_settings, qcst.manage_license, portal/ticket/agent/department/response permissions and how they affect backend access.

Where this fits in QC Support Ticket

QCST separates customer access, frontend support work, and Joomla administrator configuration. A QCST Frontend Agent can work tickets in the Agent Queue without being granted Joomla backend administration, while administrator actions remain governed by Joomla ACL and QCST-specific permissions.

Primary location: Joomla Administrator → System → Global Configuration → QC Support Ticket permissions, plus QCST role/scope controls.

Current permission map

PermissionPractical meaning
core.manage / core.adminAdministrator component access / Joomla administrative authority.
qcst.manage_settingsManage QCST configuration and organization setup.
qcst.manage_licenseManage entitlement/legacy-key controls.
qcst.use_portalUse the frontend customer portal.
qcst.submit_ticketSubmit a ticket where other checks permit it.
qcst.view_own_ticketsView the current customer's own tickets.
qcst.agent_accessEnter the frontend Agent Queue when the user also has an active QCST Agent record.
qcst.manage_ticketsPerform ticket-management actions subject to department scope.
qcst.manage_departmentsManage department-scoped organization data.
qcst.manage_responsesManage canned responses where entitled.

Two checks often apply

A Joomla/QCST permission can allow use of a feature, while ticket ownership or Agent Department scope still limits the specific record. Granting qcst.agent_access does not make every ticket visible to that Agent.

Important behavior and limits

  • The current administrator interface has nine tabs: About, Support, Status, Settings, Tickets, Canned Responses, Email Templates, Frontend Design, Frontend Text.

Key fields and behavior

ItemCurrent behavior
core.manage / core.adminBackend component administration
qcst.manage_settingsQCST settings/configuration
qcst.manage_licenseEntitlement/preview actions
qcst.use_portalUse customer portal
qcst.submit_ticketCreate tickets
qcst.view_own_ticketsView own tickets
qcst.agent_accessEnter Agent Queue
qcst.manage_ticketsTicket management actions
qcst.manage_departmentsOrganization/Department management
qcst.manage_responsesCanned response management

Design ACL around responsibilities

  • Give day-to-day Frontend Agents the frontend Agent role/scope they need; do not grant Joomla Administrator access merely so they can answer tickets.
  • Give support managers only the QCST administrator actions required for their job, such as ticket or Department management.
  • Reserve qcst.manage_license and broader Joomla core.admin capabilities for administrators who genuinely manage entitlement or global permissions.
  • After changing ACL, sign in as a normal member of the affected Joomla group and test both an allowed and denied action.

Community Discussion

For practical QC Support Ticket workflows and discussion with other Joomla site owners, visit the QC Support Ticket Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.