Roles versus permissions — getting access right
Roles are the broad shape. Permissions are the detail. Use both, in that order.
The three roles
Client sees only their own tickets in the portal. Staff work the queues they belong to. Administrator configures the system. Roles are coarse on purpose.
Then permissions
Within staff, permissions decide who can delete a ticket, view reports, export data, edit canned replies or see other departments. Grant the minimum that lets the person do their job, then add on request.
A practical starting point
Agents: reply, assign within their department, add notes. Team leads: the above plus reports, reassignment across departments and QA. Administrators: everything, with two-factor authentication required.