12.1 Overview

Roles and permissions control what each person can see and do inside AIUNIFY Call Center.

A role represents a person’s overall position within the platform. Permissions represent the individual actions that the person is authorized to perform.

For example, the Agent role may allow a user to view contacts and make calls but prevent that user from deleting contacts, changing billing settings, or managing other users.

AIUNIFY Call Center uses a structured role hierarchy to protect customer information, administrative settings, billing records, telephone configurations, and other sensitive areas of the platform.

The three primary roles are:

  1. Admin
  2. Customer
  3. Agent

Each user should be assigned the role that most closely matches their responsibilities.

12.2 How Role-Based Access Works

Every user account is connected to a role.

The assigned role contains a collection of permissions. When the user attempts to open a page or perform an action, AIUNIFY Call Center checks whether the user’s role contains the required permission.

For example:

  1. A user with permission to view campaigns may open the Campaigns page.
  2. A user with permission to create campaigns may create a new campaign.
  3. A user with permission to execute campaigns may launch, pause, resume, or stop a campaign.
  4. A user without permission to delete campaigns cannot remove one.
  5. A user with permission to make calls may use eligible calling tools.
  6. A user without permission to manage settings cannot change telephone-provider credentials.

A user may be able to view a section without being able to change its information. Viewing, creating, editing, deleting, executing, exporting, and managing are separate permissions.

12.3 Understanding the Role Hierarchy

The system uses the following hierarchy:

Level 1 — Admin

The Admin role has the highest level of authority.

Administrators manage the overall AIUNIFY Call Center platform, including customers, system settings, pricing, telephone numbers, verification records, reports, and platform-wide operations.

Level 2 — Customer

The Customer role represents a business, organization, or account owner using AIUNIFY Call Center.

Customers manage their own operational data, campaigns, contacts, agents, telephone settings, credits, and account information.

Level 3 — Agent

The Agent role represents a staff member who works under a Customer account.

Agents receive limited operational access based on the permissions assigned to the Agent role. Their access is intended primarily for calling, campaign execution, contact review, and related daily call center activities.

The hierarchy can be represented as:

Admin → Customer → Agent

An Admin oversees the platform. A Customer owns and manages a business account. An Agent works under that Customer.

12.4 Opening Roles and Permissions

To review the system’s roles:

  1. Sign in to AIUNIFY Call Center.
  2. Open the main navigation menu.
  3. Select Roles & Permissions.
  4. The Roles and Permissions page will open.

Access to this section depends on the role and permissions of the signed-in user.

Administrators normally have the broadest access to role information. Customers and Agents may have limited access or may not see this menu option.

12.5 Understanding the Roles Page

The Roles and Permissions page displays the roles currently configured in the system.

The default roles are:

  1. Admin
  2. Customer
  3. Agent

Each role may display information such as:

  1. Role name
  2. Description
  3. Hierarchy level
  4. Number of assigned permissions
  5. Number of connected users
  6. System-role status

The role description explains the intended purpose of the role.

The hierarchy level indicates the role’s position in the account structure.

The permissions count indicates how many individual actions are connected to the role.

The users count indicates how many accounts currently use that role.

12.6 The Admin Role

The Admin role provides complete platform-level authority.

An administrator may be able to manage:

  1. Customers and user accounts
  2. Agents
  3. Roles and permissions
  4. Campaigns
  5. Contacts
  6. Calls and call logs
  7. Telephone numbers
  8. Number requests
  9. Telephone-provider settings
  10. SIP trunks and BYOC connections
  11. Credit balances and transactions
  12. Billing and payment settings
  13. Pricing rules
  14. Profit reports
  15. KYC reviews and settings
  16. Languages and translations
  17. Website pages and theme content
  18. System configuration
  19. Error logs and scheduled-task monitoring

The Admin role receives all system permissions by default.

Because this role controls highly sensitive platform functions, administrator access should be assigned only to trusted platform operators.

A Customer or Agent should not be promoted to Admin simply to resolve a missing menu option. The correct permission or configuration issue should be identified instead.

12.7 The Customer Role

The Customer role is intended for a business owner or organization using AIUNIFY Call Center.

A Customer owns the business data stored within their account and may manage the Agents working under that account.

The default Customer role includes broad access to the customer’s own operational resources.

Campaign Access

Customers may generally:

  1. View campaigns
  2. Create campaigns
  3. Edit campaigns
  4. Delete campaigns
  5. Execute campaigns
  6. Review campaign analytics

Contact Access

Customers may generally:

  1. View contacts
  2. Create contacts
  3. Edit contacts
  4. Delete contacts
  5. Import contacts
  6. Export contacts
  7. Manage contact lists
  8. Manage contact tags

Call Access

Customers may generally:

  1. View call records connected to their account
  2. Place calls
  3. Review call recordings
  4. Download eligible call information
  5. Review call activity associated with their operations

Analytics Access

Customers may generally:

  1. View their account analytics
  2. Review campaign performance
  3. Review call performance
  4. Export eligible reports

Agent Access

Customers may generally:

  1. View their Agents
  2. Create Agents
  3. Edit Agents
  4. Deactivate or remove Agents
  5. Review Agent permissions

Settings Access

Customers may generally:

  1. View their account settings
  2. Edit eligible account settings
  3. Configure their telephone-provider connection
  4. Manage their own calling configuration

Billing and Credit Access

Customers may generally:

  1. View their billing information
  2. Review credit activity
  3. Add credits through configured payment methods
  4. Manage eligible billing settings

Telephone Number Access

Customers may generally:

  1. View telephone numbers connected to their account
  2. Search available numbers
  3. Submit number requests
  4. Review number-request statuses
  5. Manage eligible assigned numbers

KYC Access

Customers may generally:

  1. View their verification status
  2. Submit basic KYC information
  3. Submit business KYC information
  4. Upload required verification documents

The Customer role does not provide full platform administration. Customers cannot manage unrelated customer accounts, global pricing rules, platform-wide profit reports, or protected administrator settings.

12.8 The Agent Role

The Agent role is intended for team members performing daily call center work under a Customer account.

Agents receive more limited access than Customers.

The default Agent role may allow the user to:

  1. View assigned or available campaigns
  2. Execute authorized campaigns
  3. Review campaign analytics relevant to their work
  4. View contacts
  5. Make calls
  6. View their own call records
  7. Review eligible call recordings
  8. Review their own analytics
  9. View their profile settings
  10. View their KYC status
  11. View telephone numbers assigned to them

Agents are not normally permitted to:

  1. Create or delete customer accounts
  2. Manage other Customers
  3. Create global users
  4. Manage platform pricing
  5. Change global system settings
  6. Change telephone-provider credentials
  7. Manage customer billing
  8. Delete campaigns
  9. Delete contacts
  10. Create other Agents unless separately authorized
  11. Review platform-wide financial reports

The Agent role is designed to provide the tools necessary for operational work without exposing sensitive business or platform controls.

12.9 What Is a Permission?

A permission authorizes one specific action.

Permission names usually contain two parts:

Module.Action

For example:

campaigns.view

The first part identifies the system module.

The second part identifies the authorized action.

Common actions include:

View

Allows the user to open a section and review its information.

Create

Allows the user to add a new record.

Edit

Allows the user to change an existing record.

Delete

Allows the user to remove a record.

Execute

Allows the user to perform an operational action, such as launching a campaign.

Import

Allows the user to bring records into the system from a file.

Export

Allows the user to download data or reports.

Manage

Provides broader control over a module or group of settings.

View Own

Limits the user to records connected directly to their account or activity.

View All

Provides access to a broader collection of records within the authorized account scope.

Permission names are primarily system identifiers. The interface may display a more readable name and description.

12.10 Campaign Permissions

Campaign permissions control access to outbound calling campaigns.

Common Campaign permissions include:

View Campaigns

Allows the user to open the campaign list and review campaign details.

Create Campaign

Allows the user to create a new campaign.

Edit Campaign

Allows the user to change campaign settings, messages, schedules, contacts, and related configuration.

Delete Campaign

Allows the user to permanently remove a campaign.

Execute Campaign

Allows the user to launch, pause, resume, or stop campaign execution.

View Campaign Analytics

Allows the user to review campaign statistics and performance reports.

An Agent may need View Campaigns and Execute Campaign permissions without needing Create, Edit, or Delete permissions.

12.11 Contact Permissions

Contact permissions control access to customer and prospect records.

Common Contact permissions include:

View Contacts

Allows the user to review contact records.

Create Contacts

Allows the user to add contacts manually.

Edit Contacts

Allows the user to change contact information.

Delete Contacts

Allows the user to remove contact records.

Import Contacts

Allows the user to upload contacts from a supported file.

Export Contacts

Allows the user to download contact data.

Manage Contact Lists

Allows the user to organize contacts into lists.

Manage Contact Tags

Allows the user to apply and manage contact tags.

Agents commonly receive View Contacts permission but not full contact-management authority.

12.12 Call Permissions

Call permissions control the ability to place calls and review calling activity.

Common Call permissions include:

View Calls

Allows the user to open the Calls section.

Make Calls

Allows the user to place calls through the system.

View Own Calls

Limits the user to calls connected to their own activity.

View All Calls

Provides broader call-record access within the authorized account.

Access Recordings

Allows the user to listen to eligible call recordings.

Download Call Information

Allows the user to download eligible call data or recordings when supported.

Call permissions do not replace telephone-number assignment. A user may have permission to make calls but still require an active and properly assigned telephone number.

12.13 Analytics Permissions

Analytics permissions control access to dashboards, reports, campaign results, and call statistics.

Common Analytics permissions include:

View Analytics

Allows the user to access analytics pages.

View Own Analytics

Limits analytics to the user’s own activity.

View All Analytics

Provides broader analytics access within the account.

Export Analytics

Allows the user to download eligible reports.

Agents should normally receive only the analytics necessary to understand their own work.

Customers may require broader access to evaluate campaigns and team performance.

Administrators may access platform-wide reporting and financial analytics.

12.14 Agent Permissions

Agent-management permissions control how Customers and Administrators manage human call center representatives.

Common Agent permissions include:

View Agents

Allows the user to open the Agents section.

Create Agents

Allows the user to add a new Agent account.

Edit Agents

Allows the user to change an Agent’s information, password, status, or eligible settings.

Delete Agents

Allows the user to remove an Agent account.

Manage Agent Permissions

Allows the user to review or assign eligible access controls connected to Agents.

The current system primarily applies access through the main Agent role. Individual permission selections may appear during Agent creation or editing, but role-level permissions remain the primary source of authority.

12.15 User-Management Permissions

User permissions are different from Agent permissions.

Agent permissions normally apply to team members working under a Customer.

User-management permissions may provide access to broader platform accounts, including Customers and other account types.

These permissions should normally remain restricted to Administrators.

Examples may include:

  1. View users
  2. Create users
  3. Edit users
  4. Delete users
  5. Impersonate users
  6. Change user statuses

User impersonation allows an authorized administrator to enter another user’s account view for support or troubleshooting.

Impersonation should be used only for legitimate administrative purposes.

12.16 Settings Permissions

Settings permissions determine which configuration pages a user may access.

Common Settings permissions include:

View Settings

Allows the user to review eligible settings.

Edit Settings

Allows the user to update eligible settings.

Manage Telephone Settings

Allows the user to configure telephone-provider credentials, webhook settings, geographical permissions, and calling configuration.

Agents generally receive only basic profile-view access.

Customers may manage their own account and telephone settings.

Administrators manage platform-wide configuration.

12.17 Billing and Credit Permissions

Billing permissions control access to balances, payments, credit history, and financial settings.

Common Billing permissions include:

View Billing

Allows the user to review account billing information and transactions.

Manage Billing

Allows the user to perform eligible billing actions, such as adding credits or managing payment-related settings.

Billing access should not be assigned to Agents unless their job specifically requires it.

Customer account owners should regularly review who has access to financial information.

12.18 Telephone Number Permissions

Telephone-number permissions control access to available, requested, assigned, and active numbers.

Common Number permissions include:

View Numbers

Allows the user to review eligible telephone numbers.

Request Numbers

Allows a Customer to submit a request for an available telephone number.

Manage Numbers

May allow an Administrator to configure, assign, revoke, release, price, or synchronize numbers.

Agents with View Numbers permission normally see only numbers assigned or made available to them.

12.19 KYC Permissions

KYC permissions control access to identity and business verification.

Common KYC permissions include:

View KYC

Allows a user to review their verification status.

Submit Basic KYC

Allows a Customer to provide personal verification information.

Submit Business KYC

Allows a Customer to provide business-verification information.

Review or Approve KYC

Allows an Administrator to review documents, approve submissions, reject submissions, and manage verification settings.

Agents generally receive only permission to view their own status.

12.20 Viewing a Role

To review a role:

  1. Open Roles & Permissions.
  2. Locate the required role.
  3. Open the role details.

The Role Details page is designed to display:

  1. Role name
  2. Description
  3. Hierarchy level
  4. Number of users assigned to the role
  5. Number of permissions assigned to the role
  6. Role creation date
  7. Assigned permissions

Each assigned permission may display its name and description.

Reviewing a role is useful when a user can access some features but not others.

12.21 Reviewing the Permission Directory

AIUNIFY Call Center can group permissions according to their module.

The permission directory helps an administrator understand how available permissions are organized.

Permissions may be grouped under modules such as:

  1. Campaigns
  2. Contacts
  3. Calls
  4. Analytics
  5. Agents
  6. Users
  7. Settings
  8. Billing
  9. Numbers
  10. KYC

The modules displayed can vary as additional platform features are introduced.

A permission’s description explains what action it authorizes.

12.22 Built-In System Roles

Admin, Customer, and Agent are built-in system roles.

The current source marks all three roles as protected system roles.

Protected roles are important because the application depends on them for:

  1. Account registration
  2. Administrative access
  3. Customer ownership
  4. Agent creation
  5. Data separation
  6. Authorization policies
  7. Menu visibility
  8. API authorization
  9. Customer-to-Agent relationships

Changing or deleting one of these roles could prevent users from accessing required features or could expose protected information.

For this reason, the standard role-update process prevents system roles from being modified.

12.23 Current Permission-Editing Limitation

The interface contains pages and controls for reviewing permissions and selecting permission checkboxes.

However, the current application logic applies two important restrictions:

  1. Only an Administrator can submit role-permission changes.
  2. Protected system roles cannot be modified through the standard update process.

Because Admin, Customer, and Agent are all protected system roles, an attempt to save changes to one of these roles may produce a message similar to:

System roles cannot be modified.

This is an intentional protection in the current release.

The standard user interface also does not provide a complete create-and-delete workflow for custom roles.

Therefore, the Roles and Permissions section should currently be treated primarily as a role-review and access-reference area.

12.24 Assigning Roles to Users

Roles are normally assigned during account creation.

Administrator Accounts

Administrator accounts are created or promoted through protected administrative processes.

Customer Accounts

A new business account is normally assigned the Customer role.

Agent Accounts

An Agent created by an Administrator or Customer is assigned the Agent role.

Agents are also connected to a parent Customer account.

The role determines general access. The parent Customer relationship determines which business records the Agent is authorized to use.

A role should not be changed directly in the database unless the person performing the change fully understands the account relationships and authorization rules.

12.25 Role Access and Data Ownership

A permission does not automatically provide access to every record in the platform.

AIUNIFY Call Center also applies ownership and account-separation rules.

For example:

  1. A Customer may have permission to view Agents but sees only Agents connected to that Customer.
  2. An Agent may have permission to view calls but sees only authorized or personally connected call records.
  3. A Customer may have permission to manage campaigns but manages only campaigns belonging to that Customer account.
  4. An Administrator may have broader platform-level access.
  5. One Customer cannot normally view another Customer’s private contacts, campaigns, Agents, or billing records.

Effective access is therefore determined by:

Role + Permission + Record Ownership + Account Relationship

All four controls may affect whether a page or action is available.

12.26 Menu Visibility and Permissions

The navigation menu may change according to the signed-in user’s role and permissions.

A missing menu option may indicate that:

  1. The user’s role does not contain the required permission.
  2. The feature is restricted to another role.
  3. The account is inactive or suspended.
  4. The user must sign out and sign back in.
  5. The feature requires additional configuration.
  6. The menu is hidden because the user does not own or have access to the required records.

A visible menu option does not always guarantee that every action inside the page is available.

For example, a user may be able to open Campaigns but may not be able to delete a campaign.

12.27 Permissions and API Access

AIUNIFY Call Center also provides API functions.

API access does not automatically bypass role and permission requirements.

An authenticated API user may still be restricted according to:

  1. Assigned role
  2. Assigned permissions
  3. Account ownership
  4. API-token authority
  5. Resource policies
  6. Customer or Agent relationship

API keys and tokens should be created only for authorized integrations.

Removing a permission or deactivating a user may affect both interface and API access.

12.28 Recommended Role Practices

Use the principle of least privilege.

This means assigning only the access a person needs to complete their work.

Administrators should remain limited to trusted platform operators.

Customer accounts should be used by business owners or authorized account managers.

Agent accounts should be created separately for each staff member.

Users should never share one account.

Do not assign billing or system-setting permissions to Agents unless absolutely necessary.

Deactivate accounts immediately when a staff member leaves the organization.

Review Agent access whenever responsibilities change.

Review administrator accounts regularly.

Require strong passwords and two-factor authentication where available.

Test access using a non-administrator account before deploying a new team workflow.

Document who is responsible for approving access changes.

12.29 Example Role Assignments

Call Center Owner

Recommended role: Customer

Typical access:

  1. Campaign management
  2. Contact management
  3. Agent management
  4. Call records
  5. Analytics
  6. Billing
  7. Telephone settings
  8. Number requests

Call Center Supervisor

Current recommended role: Customer or a carefully managed account structure

A supervisor may need broader operational access than an Agent but should not receive platform-wide Admin access.

Because the current release does not provide a complete custom-role workflow, the business should carefully evaluate the required access before choosing a role.

Calling Agent

Recommended role: Agent

Typical access:

  1. View campaigns
  2. Execute campaigns
  3. View contacts
  4. Make calls
  5. Review own call records
  6. Review assigned numbers
  7. Review own analytics

Platform Operator

Recommended role: Admin

Typical access:

  1. Customer administration
  2. Global telephone management
  3. Pricing
  4. KYC review
  5. System configuration
  6. Platform reports
  7. Error and cron monitoring

12.30 Troubleshooting Roles and Permissions

A User Cannot See a Menu Option

Confirm the user’s assigned role.

Review the permissions connected to that role.

Confirm that the account is Active.

Ask the user to sign out and sign back in.

Confirm that the feature is available to that role.

A User Can View a Page but Cannot Make Changes

Viewing and editing are separate permissions.

Confirm that the role contains the required create, edit, delete, execute, or manage permission.

An Agent Can See Another Agent’s Information

Confirm that both Agents are connected to the correct parent Customer.

Review the account relationship and Agent authorization rules.

Report unexpected cross-customer visibility immediately.

A Customer Cannot Manage an Agent

Confirm that the Agent belongs to the Customer.

Confirm that the Customer role has Agent-management permissions.

Confirm that the Agent account was not created under another Customer.

Permission Changes Will Not Save

Confirm that the signed-in user is an Administrator.

Confirm whether the role is a protected system role.

Admin, Customer, and Agent are protected system roles in the current release and cannot be modified through the standard save process.

The Manage Permissions Button Opens an Error or Unsupported Page

The interface and route configuration may not provide a complete editing workflow for protected roles in the current release.

Use the role details and permission directory for review.

Do not attempt direct database changes without a tested backup and developer review.

An Agent Has Permission but Still Cannot Make Calls

Confirm that the Agent has an assigned telephone number.

Confirm that the number supports voice calling.

Confirm that telephone-provider credentials are active.

Confirm that browser microphone permission is enabled.

Confirm that the Customer account has sufficient credits.

Changes Do Not Appear Immediately

Ask the user to log out and log back in.

Clear the browser cache when necessary.

Role and permission information may be loaded when the user session begins.

12.31 Security Warning

Incorrect role or permission changes can expose:

  1. Customer contact data
  2. Call recordings
  3. Billing records
  4. Telephone-provider credentials
  5. KYC documents
  6. Platform pricing
  7. Customer account controls
  8. Administrative settings

Do not make direct database changes to roles, permissions, or user-role relationships without:

  1. A complete database backup
  2. A record of the current assignments
  3. A tested rollback plan
  4. An understanding of the authorization policies
  5. Verification using a non-production account when possible

Protected system roles should not be deleted or renamed.

12.32 Chapter Summary

AIUNIFY Call Center uses roles and permissions to control platform access.

The role hierarchy consists of Admin, Customer, and Agent.

Administrators have platform-wide authority.

Customers manage their own business operations, campaigns, contacts, Agents, numbers, billing, and settings.

Agents receive limited access for daily calling and campaign work.

Permissions control individual actions such as viewing, creating, editing, deleting, executing, importing, exporting, and managing.

Access is also affected by record ownership and Customer-to-Agent relationships.

The three built-in roles are protected system roles. The current release allows their permissions to be reviewed, but the standard update process prevents those roles from being modified.

Careful role assignment protects customer information, financial records, call activity, telephone settings, and platform administration.

Write Your Comment