User Management
Roles and permissions control what each teammate can see and change. Invite a user with a baseline role, then narrow or widen their access per feature when they need something different from the preset.
Baseline roles
Section titled “Baseline roles”Start every invite with a baseline role. It sets a sensible default across all features, which you can adjust afterward.
| Role | Access | Best for |
|---|---|---|
| Viewer | Read access across configured features. No changes to settings or content. | The safe default for most observers. |
| Editor | Updates content and configuration, without broad account-wide admin access. | Day-to-day operators. |
| Admin | Full administrative control, including high-impact settings. | Trusted owners. Grant it only when necessary. |
Permission levels
Section titled “Permission levels”Every feature is governed by one of four levels. A baseline role sets these for you; custom access lets you set them per feature.
| Level | What it grants |
|---|---|
| No Permission | The feature is hidden. The user can’t see or open it. |
| Viewer | Read-only. The user can see the feature but can’t change it. |
| Editor | The user can view and change the feature’s content and configuration. |
| Admin | Full control of the feature, including its high-impact settings. |
Not every feature offers all four levels. Some are view-only, and some skip Editor or Admin where the level wouldn’t mean anything. The available levels for each feature are listed below.
Feature reference
Section titled “Feature reference”Access is granted per feature. Each row is one selector in Customize Access; the levels shown are the ones that feature supports (every feature also supports No Permission).
| Feature | Governs | Available levels |
|---|---|---|
| Agent Configuration | How the agent is set up and behaves. | Viewer, Editor, Admin |
| Agent Knowledge | The Knowledge Base that powers answers and actions. | Viewer, Editor |
| Agent Actions | The actions the agent can run. | Viewer, Editor, Admin |
| Agent Conversations | Conversation history and transcripts. | Viewer |
| AI API Key | The AI provider key the agent runs on. | Viewer, Admin |
| Subscription Settings | Plan and subscription settings. | Viewer, Editor |
| Session Replay | Session replays of user sessions. | Viewer |
| Feature Management | Feature management and flags. | Viewer, Editor, Admin |
| Analytics | Conversational Analytics dashboards and reports. | Viewer, Admin |
| JWT Settings | JWT authentication settings. | Viewer, Editor, Admin |
Invite a user
Section titled “Invite a user”-
Open Invite User and enter the person’s Name and Email.
-
Under Choose Access Level, pick a baseline role (Viewer, Editor, or Admin). This fills in a default permission for every feature.
-
Optional: open Customize Access to override individual features. Only do this if the person needs something different from the preset.
-
Check the Effective Access panel, which summarizes exactly what the invite grants, then send the invite.
Edit a user’s access
Section titled “Edit a user’s access”Access isn’t fixed at invite time. To change it later, open Edit for that person from your team list. The controls are the same as the invite dialog: adjust the baseline role or set individual features under Customize Access, watch Effective Access update, then Save.
Customize access
Section titled “Customize access”Customize Access is for the exceptions, when one person needs more or less than any single role gives. Open Show Advanced, search for a feature, and set its level independently using the feature reference above. Each feature offers only the levels that apply to it.
Setting any feature to a level that doesn’t match the chosen role marks the user as Custom access in use, so it’s clear this person isn’t a plain Viewer, Editor, or Admin.
Effective access
Section titled “Effective access”The Effective Access panel is the source of truth for an invite or edit. It shows a running count of permissions selected (for example, “20 permissions selected”) and lists every feature with the level the user ends up with, after the baseline role and any custom overrides are combined. Confirm it reads as intended before you save.