Proposed:
Allowing conditional permissioning for the Ticket Portal to allow:
- all users within a company to access the portal and see their raised tickets
- some users (tagged with some attribute) to see all the tickets raised by those in the company
This would combat any potential sensitive data raised in a ticket.
Just to use a very extreme example a user could raise a ticket to ask how to enter leave on our system for a user experiencing personal difficulties, in this case everyone in the company would be able to see that ticket.