Users, Roles & Access

Who can see which calls, which workspaces and which screens — and how to set that up without ending up with everyone as an admin.

The access model

Three things decide what a person can do:

  1. Their role Admin, user or agent. This sets the shape of what they can reach at all.
  2. Their workspaces Users see only the workspaces they were assigned; admins see all of them.
  3. Their permissions The account's permission set decides which screens and actions render. Anything a person can't use isn't shown, so sidebars differ from person to person.

Agents add a fourth dimension: an access level that decides whether they see their calls, their performance, both, or nothing.

The three roles

CapabilityAdminUserAgent
Dashboard & call listAll workspacesAssigned workspacesOwn calls only, with Calls Access
Call analysis screenYesYesOwn calls, no Comments tab
Comments & taggingYesYesNo
Analytics chartsYesYesNo
Agents PerformanceWhole floorWhole floorOwn scorecard, with Performance Access
Upload callsYesWith upload permissionNo
Workspaces & ConfigurationYesView / edit where permittedNo
Invite users, manage agentsYesOnly with the relevant permissionNo
IntegrationsYesOnly with the relevant permissionNo
Usage, plan & billingYesOnly with the relevant permissionNo

How gating shows up

Permission gating is quiet by design, which is worth knowing before you go hunting for a missing feature:

  • Hidden, not disabled. Sidebar items, buttons and whole tabs are not rendered when the account lacks the permission — nothing is greyed out.
  • Section headers disappear too. If every item under Manage is hidden, the heading goes with it.
  • Account tabs adapt. The Account screen opens on the first tab the person can actually use, so nobody lands on a blank panel.
  • Attempting a gated action — a permission-checked button such as Invite User — reports Access Denied rather than failing silently.
"The screen isn't there"

Nine times in ten this is permissions, not a bug. Compare the person's sidebar against an admin's, then check their role and workspace assignment under All Users.

Managing users

Sidebar Manage All Users lists everyone on the account:

ColumnMeaning
Created onWhen the account or invite was created.
UserName and email.
RoleAdmin or user, badged.
WorkspacesWhich workspaces they can reach. Admins reach all.
StatusActive, or Invited while an invite is outstanding.
ActionsEdit the user, and for pending invites, resend or revoke.

The screen also carries an Invites view for outstanding invitations, and exports the list to a spreadsheet for access reviews.

Four counters above the user list: total users, active users, pending invites and requested access
The four counters above the list are the access review in miniature — total, active, pending invites, and requests waiting on a decision.
The Team Members toolbar with a search box, a role filter, Export and Invite User
Search by name or email, filter by role, Export for the access-review spreadsheet, and Invite User top right.
  1. Press Invite User Top right of All Users, or from the sidebar's invite action.
  2. Enter their work email This becomes their sign-in identity.
  3. Choose the role Admin for account owners and QA heads who need every workspace and the billing screens. User for everyone else.
  4. Select workspaces Only asked for the user role — admins get all workspaces implicitly. Pick as many as the person genuinely needs.
  5. Send They get a registration link and set their own password; nobody shares credentials.
The Invite User dialog with email, role selector, workspace selector and a Send Invite button
Email, role, and — for the user role — the workspaces they'll be able to reach. Send Invite stays disabled until the required fields are filled.

Invite states

  • Invited — the link has been sent and is waiting. The person doesn’t count as active yet.
  • Resend invite — use when the mail was missed or the link expired; it issues a fresh one.
  • Revoke invite — cancels an unaccepted invitation. Use it the moment a hire falls through.
  • Invalid link — what the recipient sees on an expired or already-used link. Resend from here.
The user table with a row per person showing avatar, name and email, role badge, workspaces, status and row actions
The full list. Active rows offer Deactivate and an edit control where the role is changed; Pending rows offer Resend and Revoke instead. A +90 more chip in the workspaces column is the signal to check whether that person needs admin rather than ninety individual grants.

The agent roster

Agents are the people whose calls you audit; they are a separate roster from users, because most agents never sign in at all. Sidebar Manage All Agents holds them:

ColumnMeaning
Org Agent IdYour own internal agent ID, if you supplied one — the join key back to your WFM or CRM.
Created onWhen the agent was added.
NameAgent name as it appears against calls.
WorkspacesWhich workspaces the agent belongs to.
StatusWhether the agent record is active.
Agent AccessTheir access level — see below.
ActionsEdit the agent, or change their access.

Add Agent takes a name, email, optional Org Agent ID, the workspaces they work in, and two access switches. The roster exports to a spreadsheet, and a KPI on the screen shows how many agents currently have access granted.

Four counters above the agent roster: total agents, active agents, agents with access granted and agents not assigned to a workspace
The fourth counter — agents Not Assigned to any workspace — is the one worth watching. Those agents' calls have nowhere to group.
The agent roster table showing org agent ID, created date, name, workspaces, status and an agent access badge per row
The roster. The Agent Access badge shows each agent's level at a glance, and the spanner beside it opens the two switches. Rows reading Not Assigned in the workspaces column are the ones to fix first.
Names must match your recordings

Calls are attributed to agents by name. If your dialer writes "R. Sharma" and the roster says "Rahul Sharma", their calls won't group. Add agents before ingesting in bulk, and keep the spelling identical to what your recording system produces.

Agent access levels

Two switches — Calls Access and Performance Access — produce four states:

LevelSwitchesWhat the agent can see
No AccessBoth offNothing. The agent has no sign-in of their own; their calls are still audited and still appear in your reporting. This is the default.
Calls AccessCalls onTheir own calls and their own call analysis — transcript, sentiment, emotions, score. No Comments tab, no other agents’ calls.
Performance AccessPerformance onTheir own scorecard only. They land directly on Agents Performance instead of the dashboard.
Full AccessBoth onTheir own calls and their own performance.

Agents never see other agents, management screens, integrations or billing, whatever the level. Self-service access is a coaching accelerator when it’s used — an agent who can hear their own flagged moment usually fixes it without a session.

Granting access in bulk

The Agent Access Control action handles the roster at once, in Grant or Revoke mode, with separate pickers for calls access and performance access. The list only offers agents the action actually applies to — Grant excludes those who already have it, Revoke only shows those who do — so you can’t accidentally no-op half a batch. Use it when a new self-service policy rolls out, and at offboarding time.

Access practices that hold up

  • Keep admins few. Admin means every workspace plus billing. Two or three is usually right.
  • Assign workspaces narrowly. A supervisor who only runs collections doesn’t need the sales workspace, and narrow access makes their dashboard more useful, not less.
  • Revoke at offboarding, don’t wait. Revoke the invite or the user, and revoke agent access in the same pass.
  • Export and review quarterly. Both lists export; a fifteen-minute quarterly read catches the access nobody remembers granting.
  • Never share logins. Comments, notifications and bookmarks are per person, and a shared login destroys the audit trail that makes QA defensible.