FAQs: Understanding Help Center Access Settings and Permissions | Zoho Desk

FAQs: Understanding Help Center Access Settings and Permissions

Access Models
What access options are available for a Help Center?
A Help Center can be configured using one of two access approaches:
  1. Require customers to register before accessing the Help Center
  2. Keep the Help Center open, but require customers to sign in before submitting tickets
These options are mutually exclusive. An organization must choose whether authentication is required for all Help Center access or only when a visitor wants to submit a ticket.
What happens when customers must register to access the Help Center?
Visitors are directed to the sign-in or registration page before they can access the Help Center.

This model is appropriate when the organization wants all Help Center activity to occur through identified customer accounts. Registered customers can track tickets, submit future tickets with their email address prefilled, review recent activity in My Area, and associate other contact channels—such as Facebook or Twitter—with the same Help Center account.
What happens when the Help Center is open but sign-in is required to submit tickets?
Visitors can browse the Help Center, search Knowledge Base articles, and view community content without signing in. However, they must authenticate before creating a ticket.

This approach is useful when an organization wants public self-service content while ensuring that all new support requests are associated with signed-in users.

For example, a software provider can allow prospective customers to read setup and troubleshooting articles, while requiring account authentication before a customer can request account-specific support.
Can registration be required while sign-in is also required only for ticket submission?
No, These are alternative access configurations, not settings to combine.

Choose Customers must register to access the Help Center when all access should require an account. Choose Customers must sign in to your Help Center to submit Tickets when articles and community content should remain publicly accessible but ticket submission should require authentication.
Can visitors submit tickets through an open Help Center?
Yes. An open Help Center allows visitors to submit tickets and search the Knowledge Base or community content.
However, visitors must sign in to track ticket status. Organizations should also consider that open access can lead to spam or irrelevant ticket submissions.
 Configuring Core Access Permissions
How are Help Center access permissions changed?
  1. Navigate to Setup > Channels > Help Center.
  2. Select the Help Center to configure.
  3. Click Access Settings under the Help Center submenu.
  4. Under Permissions, enable the preferred access option:
    1. Customers must register to access the Help Center, or
    2. Customers must sign in to your Help Center to submit Tickets.
Changes are saved immediately.
Who can modify Help Center access permissions?
Only administrators can modify Help Center permissions.

This restriction is important because these settings affect public access, customer authentication, ticket visibility, community availability, and the exposure of tickets from private departments.
What should be considered before making a Help Center fully open?
An open Help Center makes self-service easier for legitimate customers who only need to read articles or community posts. It also reduces the barrier to submitting a ticket.

The trade-off is that open access may increase spam or irrelevant tickets. Organizations should select the open model when broad accessibility is more important than requiring customer registration at the entry point.
 Community Visibility
Can the Community be hidden while keeping the Help Center available?
Yes. Disable Display Community in the Help Center under Access Settings > Permissions.

The Help Center can remain available for Knowledge Base browsing and ticket submission even when the Community is hidden.
When should the Community be hidden?
Hide the Community when the organization does not have the resources to maintain an active, useful customer forum.

A successful community requires ongoing attention. If an organization cannot monitor discussions or sustain relevant participation, keeping the Community hidden can prevent customers from encountering unanswered or outdated conversations.
How is the Community hidden from customers?
  1. Navigate to Setup > Support Channels > Help Center.
  2. Select the relevant Help Center.
  3. Click Access Settings.
  4. Under Permissions, disable Display Community in the Help Center.
The change is saved immediately.
 Shared Ticket Visibility
Can a customer see tickets created by other people in the same organization?
Yes. Enable Customers can view tickets of other users in their account in the Help Center access settings.
This setting allows users associated with the same organization account to view company tickets rather than only the tickets created from their own email address.

For example, a company’s procurement manager can review an issue submitted by a colleague and avoid submitting a duplicate request about the same order or service interruption.
What should be considered before enabling shared ticket visibility?
Shared ticket visibility increases collaboration for customer organizations, but it also broadens access to support information. Enable it only when users within the same account are intended to see one another’s tickets.

Review the possible content of tickets before enabling the setting, particularly where requests may contain sensitive operational, billing, or account information.
How is shared ticket visibility enabled?
  1. Navigate to Setup > Support Channels > Help Center.
  2. Select the Help Center.
  3. Click Access Settings.
  4. Under Permissions, enable Customers can view tickets of other users in their account.
The setting takes effect immediately.
 Private Departments and Ticket Submission
Can tickets from private departments appear in the Help Center?
Yes. Enable Display tickets from private departments in the help center when end users should be able to see tickets from those departments.

Private departments may be used for internal ticket management. Keep this option disabled when tickets from those departments should remain unavailable to customers.
How can tickets from private departments be shown?
  1. Navigate to Setup > Channels > Help Center.
  2. Select the required Help Center.
  3. Open Access Settings.
  4. Under Permissions, enable Display tickets from private departments in the help center.
The change is saved immediately.
Can customers choose a department before creating a ticket?
Yes. If more than one department exists, enable Show departments list page on choosing to submit a ticket.
Customers will then see a department catalog and can select a department before opening the ticket form. When this option is disabled, customers choose the preferred department within the ticket form instead.
When is the department list page useful?
The department list page is useful when departments represent clear customer-facing support areas, such as Billing, Technical Support, and Returns.

For example, a customer reporting an invoice issue can choose Billing before completing the ticket form, helping direct the request to the relevant department from the start.
How is the department list page enabled?
  1. Go to Setup > Channels > Help Center.
  2. Select the Help Center.
  3. Click Access Settings.
  4. Under Permissions, enable Show departments list page on choosing to submit a ticket.
The change is saved immediately.
 Cross-Site Scripting Protection
What is cross-site scripting protection for the Help Center?
Cross-site scripting, or XSS, is a security exploit in which an attacker causes malicious browser-side code to be stored and later inserted into pages viewed by other users.

Potential injection points can include Help Center search fields, feedback forms, and community posts. The impact can range from disruptive behavior to account compromise.
How does Help Center XSS protection work?
The XSS defense restricts user input using a defined whitelist. It controls where resources can be loaded from and prevents browsers from loading data from unauthorized locations.

This setting provides an additional protection layer for Help Center visitors and should be enabled unless there is a documented reason not to use it.
How is XSS protection enabled?
  1. Navigate to Setup > Channels > Help Center.
  2. Select the Help Center.
  3. Open Access Settings.
  4. Under Permissions, enable Defend your help center against Cross-site Scripting (XSS) (Recommended).
The change is saved immediately.
Are there browser requirements for XSS protection?
Yes. To mitigate cross-site scripting attacks, customers should use one of the latest three versions of a popular browser:
  1. Chrome
  2. Firefox
  3. Edge
  4. Safari
  5. Opera
Organizations supporting customers with older browsers should communicate this requirement when security protections are relevant to the Help Center experience.