Is anyone able to give me some insight from their experience in making a new Request Type, but locking it down so that it is invisible to those who are assigned the 'Customer' role for the Project space it is in, and is only able to be seen and/or modified by members of an internal 'Tech Team' group, or of the 'Site Administrator' role? We don't want any work items created under this new request type to be visible in any way to the front-end customer Portal.
I've been trying to figure out how to do this, but my fear is...If I create a new security level and security scheme and then apply this scheme to the project in question, how will doing so impact all the other work items and/or configuration within that project? Especially since this project does not currently have a security scheme associated with or applied to it.
Any insight will be appreciated. Thank you in advance.