Understand QCST Frontend and Backend Permissions

This reference maps qcst.use_portal, qcst.submit_ticket, qcst.view_own_tickets, qcst.agent_access, qcst.manage_tickets, qcst.manage_departments, qcst.manage_responses, settings/license permissions to practical access.

Where this fits in QC Support Ticket

QCST has two distinct permission layers: Joomla/QCST ACL decides whether a user may use a class of feature, while customer ownership or Frontend Agent Department scope decides which ticket records that user may act on. Frontend Agent status does not automatically grant Joomla Administrator access.

Primary location: Joomla Administrator → System → Global Configuration → QC Support Ticket permissions, plus QCST role/scope controls.

Current permission map

PermissionPractical meaning
core.manage / core.adminAdministrator component access / Joomla administrative authority.
qcst.manage_settingsManage QCST configuration and organization setup.
qcst.manage_licenseManage entitlement/legacy-key controls.
qcst.use_portalUse the frontend customer portal.
qcst.submit_ticketSubmit a ticket where other checks permit it.
qcst.view_own_ticketsView the current customer's own tickets.
qcst.agent_accessEnter the frontend Agent Queue when the user also has an active QCST Agent record.
qcst.manage_ticketsPerform ticket-management actions subject to department scope.
qcst.manage_departmentsManage department-scoped organization data.
qcst.manage_responsesManage canned responses where entitled.

Two checks often apply

A Joomla/QCST permission can allow use of a feature, while ticket ownership or Agent Department scope still limits the specific record. Granting qcst.agent_access does not make every ticket visible to that Agent.

Key fields and behavior

ItemCurrent behavior
core.manage / core.adminBackend component administration
qcst.manage_settingsQCST settings/configuration
qcst.manage_licenseEntitlement/preview actions
qcst.use_portalUse customer portal
qcst.submit_ticketCreate tickets
qcst.view_own_ticketsView own tickets
qcst.agent_accessEnter Agent Queue
qcst.manage_ticketsTicket management actions
qcst.manage_departmentsOrganization/Department management
qcst.manage_responsesCanned response management

What to remember

  • Use least-privileged normal accounts when validating authorization; Super User behavior cannot prove that customer, guest or Agent boundaries are correct.

Permission is necessary but may not be sufficient

A user can possess a QCST action such as qcst.manage_tickets or qcst.agent_access and still be denied a particular ticket because ownership or Department scope fails. Conversely, being listed as a Frontend Agent does not grant administrator Settings or entitlement access. Diagnose “access denied” by identifying both the capability being requested and the record scope being acted on.


Community Discussion

For practical QC Support Ticket workflows and discussion with other Joomla site owners, visit the QC Support Ticket Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.