Skip to content

Platform operator overview

This chapter is short and separate on purpose. It is for the people who run VoDialer for many call centres. If you work inside one call centre, you can skip it.

An operator is a person who looks after the platform as a whole: which companies exist, what each may use, what it costs, whether everything is healthy, and how to stop things. In the product and the API a company is called a tenant.

Operators work in a console of their own at /platform. Signing in with an operator account lands there, not in a customer’s workspace. A company user who opens /platform is sent back to their own home page.

The console looks like the rest of the product (same components, same themes) but is set apart on purpose, so nobody mistakes it for a customer’s workspace: the top-left block says VoDialer platform with a Platform label and your role, and it uses a violet accent that no customer screen uses. The top bar has a violet line and a Platform tag.

The sidebar, in this order: Overview, Companies, Billing, Operations, Compliance, Bots, People, Search, Audit, Settings, Operators. Your account page (two-step sign-in, password, theme) is in the menu at the bottom of the sidebar.

Every action button follows your role. A platform_readonly operator sees no action buttons at all. Support cannot change plans or billing. Billing cannot use view as. The server decides in the end; the screen only hides what it would refuse.

Far-reaching actions (suspending a company, the kill switch, replacing a do-not-call list, suspending a bot version, scheduling a closing) open a confirm box that states the consequence in one sentence, asks for a reason where one is required, and for the most serious asks you to type a word first.

When you use view as, the customer app opens with a banner saying you are viewing the company read-only. The sidebar there shows Back to platform, and the banner has Stop viewing.

An operator has their own account. They belong to no company, and the database refuses to give an operator a company membership (or to promote a company member). An operator signs in with the same e-mail and password form as everyone, but their session has no workspace.

The first operator is created by the demo seed (admin@vodialer.test). More are added in Operators with Add operator; the new person gets a temporary password, shown once. See two-step sign-in for what happens at the first sign-in.

Role What it can do
platform_owner Everything: reads, companies, plans, billing, global compliance data, the kill switch, media nodes, maintenance, view as, people, bot governance, announcements and flags, and managing operators.
platform_support Reads. Create, edit, suspend, resume and schedule closing of companies. View as a company. Reset a person’s password, disable them, sign them out, reset their two-step sign-in. Suspend a bot version. Not plans, not billing.
platform_billing Reads. Plans and limits. The price book and invoice records. Not view as, not people.
platform_readonly Reads only. A read of a company’s data is still recorded.

Operators shows this table on screen (GET /api/platform/v1/roles serves it). Every route is registered with exactly one required capability. A route with none answers 403.

Every platform call passes the same guard, in this order:

  1. A cookie session. API keys never work here.
  2. The person must be an operator. A company user who knocks is refused, and the attempt is recorded as platform.access_denied.
  3. Two-step sign-in must be done. See two-step sign-in.
  4. The role must hold the capability for that route.
  5. The handler runs.
  6. Exactly one line is written to the platform audit log, whatever the outcome.

If that line cannot be written, the caller gets 503 audit_unavailable instead of the data.

Each line holds who (name, e-mail, role), what, which company, the reason where one is required, the caller’s address, the HTTP status and details. The log cannot be edited or deleted, and each line carries a hash of the one before it. Audit has a Verify button that recomputes the chain and says where it breaks, if it does (GET /api/platform/v1/audit/verify).

A company sees what concerns it in its own audit log too: every platform change to the company, a person or its plan, and every request of a view as session.

People finds anyone across companies and opens their memberships and actions. Search takes one box (company, e-mail, phone, call, journey or user id) and groups the results; phone results show counts and company names only, never the number. Audit lists every operator action with filters and the Verify button. Settings holds announcements, feature flags, maintenance mode and the read-only AI provider. Operators manages operator accounts.

The overview page itself shows six platform-wide numbers (companies, calls on the phone now, agents online, calls today, AI minutes today, dropped calls over 30 days), a Needs attention list (services not answering, queues backing up, failed deliveries, recording gaps, rules not reviewed by counsel, companies near their AI minutes) and the Dialing card with the kill switch. A source that did not answer shows a dash, never zero.