Panewell for Zendesk: Documentation
Panewell shows your BI dashboards inside Zendesk Support, filtered to the customer on screen: in the ticket sidebar, on user and organization profiles, and on a full Panewell page in the left navigation bar. It runs in the agent's browser and keeps its settings in your Zendesk account.
Getting started
- An admin installs Panewell from the Zendesk Marketplace (Standard plan, $5 per agent per month after a 14-day trial).
- Open Panewell from the left navigation bar and choose Set up (admins only).
- Click New panel, name the tab, and paste the link from your BI tool's share or embed dialog.
- Allow the dashboard's host when Panewell asks.
- Add a filter, choose where the panel shows, enter a ticket number and click Preview. When it looks right, click Save panel. Agents see it the next time they open a ticket.
Supported tools and links
| Tool | Paste this | Filters | Agents sign in? |
|---|---|---|---|
| Looker Studio | The report link or its embed link (File > Embed report, with embedding on) | Report URL parameters, for example ds0.customer_id. In the report, turn on "Allow to be modified in report URL" for each parameter | Whoever the report is shared with; agents may need to be signed in to Google |
| Looker (Google Cloud core) | The dashboard or Look URL; Panewell turns it into the private embed link | Dashboard filter names, for example Customer ID | Yes, with their Looker account. A Looker admin adds the Zendesk domains (below) to the embedded domain allowlist |
| Metabase | A public link (Sharing > public link) or the normal dashboard URL | Filter slugs from the dashboard URL, for example customer_id. Public links can hide the filter widgets Panewell sets | Public links: no. Normal links: yes, and your Metabase must allow embedding from the Zendesk domains (a Metabase Pro or Enterprise setting) |
| Tableau | A Tableau Public viz link, or a Tableau Cloud or Server view URL | Field or parameter names, for example Customer ID | Tableau Public: no. Cloud and Server: yes |
| Power BI | A report URL, or a secure embed link (File > Embed report > Website or portal), or a publish-to-web link | Table/Field, for example Customers/Email; tick Number for numeric columns. Publish-to-web links cannot be filtered | Secure embed: yes, with their Microsoft account and a Power BI license that lets them view the report |
| Grafana | The dashboard URL (with /d/) or a public dashboard link | Dashboard variables, for example customer (sent as var-customer). Public dashboards cannot be filtered | Yes for dashboards, no for public dashboards. Grafana must allow embedding (allow_embedding) |
| Google Sheets | A published chart or sheet link (chart menu > Publish chart > Embed, the link inside src="...") | None: the same chart everywhere | No |
| Any other page | Any https URL. Put tokens anywhere after the host, for example .../customers/{{requester.external_id}} | Query parameters, plus tokens in the link | Depends on the page |
Not supported: embedding that needs a secret on a server to sign each link: Metabase static
embedding (/embed/dashboard/<token>), Looker signed embed URLs (/login/embed/...), Power BI
Embedded with embed tokens, and Tableau connected apps or trusted tickets. Panewell tells you when
you paste one of these. Use the public or sign-in link of the same dashboard instead.
Sign-in pages. The panel may only go to allowed hosts, and that includes the pages it is sent
to for signing in. When a link needs agents to sign in, the editor offers to allow the tool's own
sign-in host (accounts.google.com for Looker Studio, login.microsoftonline.com for Power BI,
sso.online.tableau.com for Tableau Cloud). If your company signs in through its own page (Okta,
Entra ID, Google Workspace SSO and similar), add that host as well, or agents sign in once with
Open full size.
Letting your BI tool be shown in Zendesk. Panewell shows dashboards inside a frame in Zendesk.
Tools that restrict where they can be framed must allow these origins: your Zendesk address
(https://yourcompany.zendesk.com) and Zendesk's app host (https://*.apps.zdusercontent.com). If
the frame stays blank or says it refused to connect, that setting is the usual cause; the editor's
preview shows the hint for each tool.
Filters and tokens
A filter is "BI parameter = Zendesk value". The Zendesk values (tokens) are:
| Token | Value |
|---|---|
requester.email, requester.email_domain, requester.external_id, requester.id, requester.name | The ticket's requester, or on a user profile, that user |
requester.field.<key> | A user field, by its field key |
organization.id, organization.external_id, organization.name, organization.field.<key> | The ticket's organization, the user's (first) organization, or the organization profile |
ticket.id, ticket.brand.id, ticket.brand.name, ticket.group.id, ticket.form.id, ticket.field.<id> | The ticket (ticket sidebar only); custom ticket fields by numeric id |
agent.id, agent.email | The signed-in agent (everywhere, including the Panewell page) |
Spellings like ticket.requester.external_id, ticket.requester.externalId, user.email and
ticket.custom_field_360012345 are accepted too. Drop-down fields give their tag value,
checkboxes true or false, multi-select fields their tags joined with commas.
If a value is empty, the panel is not loaded and says which value is missing. Panewell never shows a dashboard unfiltered in place of a filtered one.
Values are URL-encoded for the place they go: they can never change the host, add a path segment or add a parameter.
Where panels show, and for whom
| Setting | What it does |
|---|---|
| Show in | Ticket sidebar, user profile sidebar, organization sidebar, the Panewell page in the navigation bar (any combination). The editor tells you when a token has no value in a place you ticked, for example a ticket field on an organization profile |
| Height | Small 260 px, Medium 420 px, Large 620 px, Extra large 860 px. Agents can also click Open full size |
| On tickets of these brands | Ticket sidebar only. None ticked: every brand |
| For agents in these groups | None ticked: every agent. Admins always see every panel, so they can check them |
| Only show when a value matches | For example Organization field: Plan is one of enterprise, premium. Case does not matter |
Several panels in one place become tabs, in the order of the panel list (Up and Down). Only the open tab loads.
Link buttons are a panel kind: up to 8 buttons that open a page in a new browser tab, with tokens in their links, for example your admin tool's customer page.
Allowed hosts
Panewell only shows https pages from the hosts on this list: one host per line, or *.example.com
for every subdomain of example.com. IP addresses, localhost and broad wildcards (such as
*.vercel.app) are refused. The list is checked when a panel is saved and again every time a link
is built, and the sidebar page itself refuses frames from any other host. Removing a host warns you
which panels would stop.
Data and security
- Panewell reads only the values its panels use, through Zendesk, as the signed-in agent.
- The only thing that leaves Zendesk is each panel's link with its filter values, loaded by the agent's browser from an allowed host, with no referrer.
- Public links (Metabase, Tableau Public, Power BI publish to web, Grafana public dashboards, Google Sheets) can be opened by anyone who has the link, and their URL filters can be changed by whoever opens them. The editor warns you when a public link carries a customer filter. For customer data, prefer links your agents sign in to, and restrict rows in the BI tool itself (for example Power BI row-level security): URL filters choose what is shown first, they are not access control.
- Settings live in the app's own settings in your Zendesk; uninstalling removes them. Panewell creates nothing else in your account.
Troubleshooting
| What you see | Why, and what to do |
|---|---|
| "... is empty here, so this dashboard is not shown" | That customer has no value for the token (often the external ID). Fill it in Zendesk, or filter by a value every customer has |
| A blank frame, or "refused to connect" | The BI tool does not allow being framed by Zendesk. Allow the two origins above in its embedding settings |
| The panel goes blank when an agent clicks Sign in | The sign-in page's host is not allowed. Allow it in Set up (the editor suggests the tool's own), or sign in once with Open full size |
| A sign-in page inside the panel | Login-based links ask each agent to sign in once. Some browsers block sign-in inside frames unless the BI site may use cookies there; Open full size signs in in a new tab |
| "... is not on this account's list of allowed hosts" | An admin adds the host in Set up > Allowed hosts |
| The dashboard ignores the filter | The parameter name does not match the tool's filter: check the spelling in the tool (for Looker Studio, the parameter must allow changes from the report URL) |
| An agent does not see a panel | It is limited to groups they are not in, to other brands, or its condition does not match this record |
Support
Email hello@greatwork.company (Monday to Friday, US Central time). We reply within one business day. Please do not send customer data or dashboard links that contain it.