How QCST Enforces Agent Department Scope on Every Ticket Action

This article explains server-side department authorization for viewing, replying, assigning, status changes, bulk actions, attachments, relationships, merge, and split.

Where this fits in QC Support Ticket

A Frontend Agent must have an active QCST Agent record and the ticket Department must fall within that Agent’s current scope. QCST rechecks that relationship on protected ticket actions; hiding a button in the browser is not the security boundary.

Primary location: QC Support Ticket frontend and administrator interfaces, depending on the permission or failure being tested.

Before you begin

  • Use a normal Frontend Agent account for verification. Testing only as Joomla Super User can hide Department-scope or menu-access problems.

Actions that recheck scope

  • Opening/detailing a ticket
  • Public replies and Pro Internal Notes
  • Assignment/reassignment/unassignment
  • Status/Priority/Label changes
  • Bulk actions
  • Attachment access
  • Max relationships, Merge and Split

The server uses the ticket's Department plus the Agent's active QCST scope when authorizing the request. Removing UI buttons is usability; the server-side check is the security control.

Verify the result

  • The Department appears with the intended Published state and description in Settings.
  • A ticket submitted to that Department appears only to eligible Agents in that Department scope.
  • The test Agent can open the Agent Queue and see allowed-Department tickets.
  • The same Agent is denied or does not receive tickets outside the configured Department scope.

Scope changes take effect as authorization changes

When an administrator removes an Agent from a Department, do not rely on old open browser tabs or cached queue lists as proof that access remains valid. Protected actions are rechecked server-side against current scope. Test by attempting to reopen or act on an out-of-scope ticket after the change; the operation should fail even if the Agent previously worked that ticket.


Community Discussion

For practical QC Support Ticket workflows and discussion with other Joomla site owners, visit the QC Support Ticket Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.