Start a conversation

Using a Service/Shared Account for Automations (Administrator Role Required)

Overview

If your Kayako automation needs to run under a non-personal (team-owned) account, the account must have sufficient administrative permissions. In most cases, there was no error message; the automation was blocked because the shared mailbox user in Kayako was assigned to the Customer role, which lacks sufficient permissions.

Solution

Issue (Service Request)

An automation is needed to run under a non-personal “service account” instead of an individual user’s credentials.

Root Cause

The Kayako user tied to the shared/team mailbox was configured with the Customer role. This role does not have the administrative permissions required for SSL certificate management/updates.

Resolution Steps

  1. Choose the service-account identity (shared mailbox)

    Provide the exact shared/team mailbox address that should own the automation account, for example:

    • <shared_mailbox@example.com>
  2. This ensures the account is team-owned (not tied to an individual).

  3. Ensure the Kayako user exists for that mailbox
    • If the user already exists in Kayako, confirm the email address matches the shared mailbox address exactly.
    • If it does not exist, create the user using the shared mailbox address (or use your standard SaaS request process to have it created).
  4. Update permissions by changing the role to Administrator

    Update the Kayako user role as follows:

    • From: Customer
    • To: Administrator

Verification (How to Confirm It Worked)

  1. Confirm the service account shows the Administrator role in Kayako user management.
  2. Re-run the automation workflow and confirm it completes the SSL certificate update steps without permission failures.
Choose files or drag and drop files
Was this article helpful?
Yes
No
  1. ATLAS KBA

  2. Posted

Comments