Roles & Permissions
Every workspace member holds exactly one of four roles. Roles are enforced in the API, not merely hidden in the UI — a request a role isn’t allowed to make is rejected by the server even when sent directly. Role changes take effect within seconds, with no re-login required.
The four roles at a glance
| Role | Intended for | Summary |
|---|---|---|
| Admin | Workspace owner, billing owner | Full control: settings, billing, credentials, team, and every destructive action. |
| Manager | Team lead running the operation | Builds and runs everything day-to-day, but cannot touch billing, team or workspace settings. |
| Recruiter | Day-to-day operator | Runs campaigns, batches and WhatsApp sends. Cannot configure agents or infrastructure. |
| Viewer | Stakeholder, auditor, observer | Read-only everywhere. Cannot change anything. |
What each role can do
✓ = allowed. A blank cell means the API rejects it. “Own” means the member can act on their own account only.
| Area / action | Admin | Manager | Recruiter | Viewer |
|---|---|---|---|---|
| View dashboard, call history, ratings, recordings | ✓ | ✓ | ✓ | ✓ |
| Create, edit & clone agents | ✓ | ✓ | ||
| Delete an agent | ✓ | |||
| Place a test call | ✓ | ✓ | ||
| Create & launch campaigns | ✓ | ✓ | ✓ | |
| Delete a campaign | ✓ | |||
| Create, launch, pause & retry batches | ✓ | ✓ | ✓ | |
| Delete a batch | ✓ | ✓ | ||
| Send WhatsApp campaigns | ✓ | ✓ | ✓ | |
| Knowledge bases & rating templates | ✓ | ✓ | ||
| Manage phone numbers | ✓ | ✓ | ||
| Buy or release a number | ✓ | |||
| Provider credentials (Plivo, Gemini, Sarvam, Cartesia) | ✓ | ✓ | ||
| Integrations (Google Calendar and similar) | ✓ | ✓ | ||
| Wallet, top-ups & auto-recharge | ✓ | |||
| Invoices & payment receipts | ✓ | |||
| Workspace settings & team management | ✓ | |||
| API keys & webhooks | ✓ | |||
| Change own password & 2FA | Own | Own | Own | Own |
Admin
The only role that can spend money or change who has access. Give it to the person who owns the account.
- Billing: add funds, view invoices and receipts, configure auto-recharge.
- Team: invite members, change roles, remove members.
- Workspace: company profile, GSTIN, timezone, storage and recording retention.
- Developer: issue and revoke API keys, configure webhook subscriptions.
- Numbers: buy a number, release a number.
- Destructive actions: deleting an agent or a campaign is admin-only.
- Everything a Manager can do.
Manager
Builds and runs the operation. A Manager can configure anything that affects how calls are made, but cannot spend money or change the team.
- Agents: create, edit, clone, place test calls, change prompts, voices and engines.
- Campaigns & batches: create, launch, pause, resume, retry. Can delete batches.
- Knowledge bases & rating templates: full control.
- Numbers: assign a number to an agent and edit labels — but not buy or release one.
- Credentials & integrations: connect provider keys and Google Calendar.
- Cannot: wallet, invoices, workspace settings, team, API keys, or delete an agent or campaign.
Recruiter
The day-to-day operator. Runs the work that already exists, without being able to change how the system is configured.
- Campaigns: create, upload recipients, launch, pause, resume, retry.
- Batches: create from a CSV, launch, pause, retry failed calls.
- WhatsApp: create and send campaigns.
- Review: read transcripts, ratings and recordings; export results.
- Cannot: create or edit agents, manage numbers, touch credentials, or see billing.
Viewer
Read-only. Useful for a client, an auditor, or a stakeholder who needs visibility with no risk attached.
- Can see: dashboard, call history, transcripts, ratings, recordings, analytics and documentation.
- Cannot: launch anything, change anything, or view billing.
Changing someone’s role
- Open Workplace > Team (Admin only).
- Find the member and pick a new role.
- The change applies within seconds — the member does not need to sign out and back in.