I'd like to restrict the majority of our portal customers to only be able to view the issues that they submit themselves. When I have their Organization linked to the ticket, these users are able to see all other tickets related to the Org, regardless of who created them. Unlinking the Org drops portal visibility down to user generated issues.
I would like to be able to keep the Org tied to the issue. I would also like to have a separate user role that would still be able to see all tickets across the org from within the portal. Ideally this would all happen without the need for Help Desk agents to manually set security levels. Wondering if there are opinions about setting this up using Groups vs Project Roles, how best to implement.