Control case creation and workflow access

Configure these rules on the existing case type and workflow. Workspace does not introduce a separate permission system.

Set a case type's Creation policy to Governed, then select the existing owner access group, permitted creation sources, and access groups whose effective members may create the case. The creator group is only a creation gate and receives no case-wide ACL grant. Workspace derives the requester from the authenticated session, grants that identity commenter on the case, and derives the initial owner group from the case type. Existing case types remain in Legacy mode until you opt in.

To restrict a manual workflow transition, add the actor_access_group admission and select the permitted access groups. This admission only narrows existing authorization: the actor still needs the functional scope and at least the editor ResourceACL role on the case.

Use the existing crm.case.requester_replied fact on a separate automatic transition when a later requester reply should move the case. The initial submission comment does not publish this fact.