Roles and permissions
Every person in a company has one role per company. The web app reads the table below to decide what to show. The server is the authority: the gateway checks the role on every request, so hiding a button is never the only protection. If the two ever disagree, the server wins. To change a person’s role see team and roles.
The eight roles
Section titled “The eight roles”| Role | In one line |
|---|---|
| Owner | Everything, including billing and sub-accounts. At least one owner always exists. |
| Admin | Everything except owner-only items. Can assign every role but Owner. |
| Supervisor | Runs the floor: starts and stops campaigns, listens in, sees people and results. Cannot change setup. |
| Agent | Takes calls at the desk. |
| Licensed agent | An agent who may take hand-overs that need a licence. |
Quality reviewer (qa) |
Reviews calls and results. Reads everywhere. Writes only quality work. |
| Compliance | Owns safety rules and records. Reads everywhere. Writes only safety. |
| Client viewer | Looks at numbers only. Nothing can be changed. |
Who sees which screen
Section titled “Who sees which screen”Yes means the screen is in the menu. The new design calls Today “Home” and Desk “My desk”.
| Screen | Owner | Admin | Supervisor | Agent | Licensed agent | QA | Compliance | Client viewer |
|---|---|---|---|---|---|---|---|---|
| Today | yes | yes | yes | no | no | yes | yes | yes |
| Campaigns | yes | yes | yes | no | no | no | no | yes |
| People | yes | yes | yes | no | no | no | yes | no |
| Live | yes | yes | yes | no | no | no | no | no |
| Desk | no | no | yes | yes | yes | no | no | no |
| Quality | yes | yes | yes | no | no | yes | yes | no |
| Safety | yes | yes | yes | no | no | no | yes | no |
| Results | yes | yes | yes | no | no | yes | no | yes |
| Setup | yes | yes | no | no | no | no | no | no |
After sign-in a person lands on Today if they can see it, otherwise on the Desk, otherwise on Quality.
Who may do what
Section titled “Who may do what”| Action | Who |
|---|---|
| Start, pause and stop a campaign | Owner, Admin, Supervisor |
| Create or edit a campaign | Owner, Admin |
| Import lists | Owner, Admin |
| Reveal full phone numbers | Owner, Admin, Compliance |
| Listen in, whisper, take over a live call | Owner, Admin, Supervisor |
| Review a call (confirm or change an answer) | Owner, Admin, Quality reviewer |
| Edit scorecards | Owner, Admin |
| Edit safety (do-not-call list, consent, rules) | Owner, Admin, Compliance |
| Set up bots, team, phone numbers, integrations, company details | Owner, Admin |
| See the Setup billing page | Owner, Admin |
| Manage billing | Owner |
| Create sub-accounts | Owner |
| See people’s names instead of ids | Owner, Admin, Supervisor |
| Take calls at the desk | Agent, Licensed agent, Supervisor |
What the server allows
Section titled “What the server allows”The gateway applies a coarse gate before any service sees the request.
- Owner and Admin: everything the services allow.
- Supervisor: everything except changing setup (clients, bots, queues, campaigns, lists, result and pause codes, trunks, inbound routes, media nodes, caller IDs, integrations, safety, scorecards).
- QA: reads everywhere, writes only quality.
- Compliance: reads everywhere, writes only safety.
- Client viewer: reads only.
- Agent and licensed agent: an allow-list only: their own state, stats and licences, journeys, leads and callbacks, dialing a person they hold, skipping, and the media connection.
Inside the safety service, actions that only make calling stricter (adding a number to the do-not-call list, revoking consent) are open to more roles than actions that could loosen a rule, which need Owner, Admin or Compliance. The gateway gate above is applied first.
Masking by role
Section titled “Masking by role”- Supervisor, QA and Client viewer see phone numbers as
…1234(last four digits), also in the live feed. - Answers marked sensitive in a bot’s fields are masked (
••••73) except for Owner, Admin, Supervisor and Licensed agent. A Client viewer sees no birth dates. - A preview-dial card shows the full number only to Owner, Admin, Agent and Licensed agent.
- Attempt lists show only the last four digits to everyone.
- Transcript text goes only to roles that may read transcripts: Owner, Admin, Supervisor, QA and Compliance.
Operators of the platform are a separate set of roles, described in the platform overview.