Veytrix AI

Roles & Permissions

Every workspace member holds exactly one of four roles. Roles are enforced in the API, not merely hidden in the UI — a request a role isn’t allowed to make is rejected by the server even when sent directly. Role changes take effect within seconds, with no re-login required.

The four roles at a glance

RoleIntended forSummary
AdminWorkspace owner, billing ownerFull control: settings, billing, credentials, team, and every destructive action.
ManagerTeam lead running the operationBuilds and runs everything day-to-day, but cannot touch billing, team or workspace settings.
RecruiterDay-to-day operatorRuns campaigns, batches and WhatsApp sends. Cannot configure agents or infrastructure.
ViewerStakeholder, auditor, observerRead-only everywhere. Cannot change anything.
An unrecognised or missing role is treated as Viewer. Access fails closed, never open.

What each role can do

✓ = allowed. A blank cell means the API rejects it. “Own” means the member can act on their own account only.

Area / actionAdminManagerRecruiterViewer
View dashboard, call history, ratings, recordings
Create, edit & clone agents
Delete an agent
Place a test call
Create & launch campaigns
Delete a campaign
Create, launch, pause & retry batches
Delete a batch
Send WhatsApp campaigns
Knowledge bases & rating templates
Manage phone numbers
Buy or release a number
Provider credentials (Plivo, Gemini, Sarvam, Cartesia)
Integrations (Google Calendar and similar)
Wallet, top-ups & auto-recharge
Invoices & payment receipts
Workspace settings & team management
API keys & webhooks
Change own password & 2FAOwnOwnOwnOwn

Admin

The only role that can spend money or change who has access. Give it to the person who owns the account.

  • Billing: add funds, view invoices and receipts, configure auto-recharge.
  • Team: invite members, change roles, remove members.
  • Workspace: company profile, GSTIN, timezone, storage and recording retention.
  • Developer: issue and revoke API keys, configure webhook subscriptions.
  • Numbers: buy a number, release a number.
  • Destructive actions: deleting an agent or a campaign is admin-only.
  • Everything a Manager can do.

Manager

Builds and runs the operation. A Manager can configure anything that affects how calls are made, but cannot spend money or change the team.

  • Agents: create, edit, clone, place test calls, change prompts, voices and engines.
  • Campaigns & batches: create, launch, pause, resume, retry. Can delete batches.
  • Knowledge bases & rating templates: full control.
  • Numbers: assign a number to an agent and edit labels — but not buy or release one.
  • Credentials & integrations: connect provider keys and Google Calendar.
  • Cannot: wallet, invoices, workspace settings, team, API keys, or delete an agent or campaign.

Recruiter

The day-to-day operator. Runs the work that already exists, without being able to change how the system is configured.

  • Campaigns: create, upload recipients, launch, pause, resume, retry.
  • Batches: create from a CSV, launch, pause, retry failed calls.
  • WhatsApp: create and send campaigns.
  • Review: read transcripts, ratings and recordings; export results.
  • Cannot: create or edit agents, manage numbers, touch credentials, or see billing.
Recruiter is the right default for most of a team. It is enough to run outreach every day, and it removes the risk of someone changing an agent’s prompt or provider keys in the middle of a campaign.

Viewer

Read-only. Useful for a client, an auditor, or a stakeholder who needs visibility with no risk attached.

  • Can see: dashboard, call history, transcripts, ratings, recordings, analytics and documentation.
  • Cannot: launch anything, change anything, or view billing.

Changing someone’s role

  1. Open Workplace > Team (Admin only).
  2. Find the member and pick a new role.
  3. The change applies within seconds — the member does not need to sign out and back in.
An API key is a service principal, not a person. It acts with admin-level rights on the routes it can reach — agents, campaigns, batches, calls, ratings, analytics, numbers and recordings — and can never reach settings, billing or credential routes. Treat one like a password: anyone holding it can launch calls that spend your wallet. Revoke it from API Keys if it leaks.
VeytrixAI System Status