Agents can see tickets outside of assigned groups

Infos:

  • Used Zammad version: 6.4.0-1732617118.28f54743.bookworm
  • Used Zammad installation type: package
  • Operating system: Debian 12
  • Browser + version: MS Edge / Chrome

Expected behavior:

  • Only tickets inside assigned group(s) are visible

Actual behavior:

  • User has full agent rights on 1 group. He can also see tickets from another group he has no assigned rights for.

Not sure what causes this. We setup this user as an agent with access rights to one group. The user can see and interact with tickets from our other group.

Any suggestions to prevent this?

Two possibilities:

  • the organisation the agent is part of is a sharing organization. So the agent in question doesn’t see all tickets, but the tickets their colleagues are ticket customers in.
  • you have read permission as e.g. default assignment for all agents or something like that