SupportMesh Docs
Workspace Setup and Roles
Learn where workspace configuration lives, what can be customized today, and how to think about roles without over-promising exact role restrictions.
Workspace settings overview
Workspace settings live in the authenticated admin area. Current settings include workspace profile details, ticket prefix and defaults, SLA settings, branding fields, and Email Intake configuration.
- Workspace name
- Support contact email when configured
- Default timezone and locale
- Ticket prefix and ticket defaults
- Branding fields such as logo path, primary color, and portal title
- Inbound email route and triage defaults
Workspace slug and URL
The workspace slug is selected during creation and becomes part of the workspace URL. This guide only covers the workspace URL behavior that is implemented in the current product.
Branding and plan-aware settings
Branding controls are available in the settings UI, but the product already warns that some branding customizations depend on the active plan. When a setting is plan-gated, SupportMesh keeps the default product branding in place.
Roles and access
SupportMesh currently uses these workspace and client roles: Tenant Owner, Tenant Administrator, Support Manager, Support Agent, Tenant Viewer, Client Manager, and Client User.
| Role | High-level guidance |
|---|---|
| Tenant Owner | Owns workspace-level administration and can manage operational configuration. |
| Tenant Administrator | Manages workspace operations without transferring ownership. |
| Support Manager | Leads operational support workflows, ticket handling, and related support records. |
| Support Agent | Works assigned support items and ticket workflows. |
| Tenant Viewer | Has limited read-focused workspace access. |
| Client Manager | Uses the client portal in the context of a client organization. |
| Client User | Uses the client portal without internal workspace administration rights. |
Permission wording
The product enforces permission checks in the database and server actions. When a task depends on a capability such as managing clients, support items, API keys, or webhooks, treat it as available only to roles that hold the required permission in your workspace.