I run a support desk on JSM for customers of our software package. They raised support tickets with us via a subdomain, https://support.ourdomain.com/.
We have taken on a new customer that is in a different time zone than us, so we have enlisted a third party support company to look after support for that specific customer. They will be using our Jira instance to handle this.
I want to isolate those users so they're only able to see tickets/info related to the customer they look after, and not see details of other customers on our support portal.
What is the best way to do this? From my reading, it seems there are two approaches:
1) Create a separate JSM instance specifically for that customer, and then just give our 3rd party support agents access to that project.
2) Using issue security and setting security principles up to restrict their view.
I'm wondering what is considered best practice in terms of JSM? It seems both options have pros and cons. At the moment I'm leaning towards option 1, creating a separate instance, however I'd rather make sure that I'm not being short sighted with my approach.
Thank you.