A role is a named set of permissions, and every agent gets one or more roles. EPAV Desk ships with two roles, Admin and Agent; you can create others under Admin > Teammates > Roles to give someone exactly the access they need.
How roles combine
An agent may hold several roles at once. What they can do is everything allowed by at least one of their roles: permissions add up and never cancel each other. Every agent needs at least one role.
Default roles
| Role | What it allows |
|---|---|
| Admin | Every permission listed below except Send messages as contact. The role is locked: it cannot be changed or deleted. For a variation, create a new role. |
| Agent | Work with conversations: see all of them, reply, write private notes, assign agents and teams, change status, priority and tags, keep personal views. It cannot start a new conversation from the panel, and it has no admin pages, no contacts and no reports. You can change this role but not delete it. |
Your own account on a new platform has the Admin role. Give colleagues who answer customers the Agent role.
Permissions in the panel
When you edit a role, the permissions are grouped into Conversation, Admin and Contact. Each one has a label in the panel and a code of the form object:action; the code is the name the API uses. Anything left unticked is denied.
Conversation permissions
| Permission | Code | What it allows |
|---|---|---|
| View conversation | conversations:read |
Open a conversation, see who takes part, search conversations. Required to open any conversation: without it the lists below may still show conversations, but none of them opens. |
| Create conversation | conversations:write |
Start a new conversation from the panel. |
| View conversations assigned to me | conversations:read_assigned |
See the conversations assigned to this agent. |
| View all conversations | conversations:read_all |
See every conversation, whoever holds it. |
| View all unassigned conversations | conversations:read_unassigned |
See conversations that have neither a team nor an agent. |
| View conversations in team inbox | conversations:read_team_inbox |
See conversations of the agent's teams that no agent has taken yet. |
| View your team conversations | conversations:read_team_all |
See every conversation of the agent's teams, taken or not. |
| Assign conversations to users | conversations:update_user_assignee |
Set or remove the agent of a conversation. |
| Assign conversations to teams | conversations:update_team_assignee |
Set or remove the team of a conversation. |
| Change conversation priority | conversations:update_priority |
Set the priority. |
| Change conversation status | conversations:update_status |
Open, snooze, resolve or close a conversation. |
| Add or remove conversation tags | conversations:update_tags |
Tag conversations. |
| View conversation messages | messages:read |
Read and search messages, download a transcript. |
| Send messages in conversations | messages:write |
Reply to customers and resend a failed message. |
| Send private notes in conversations | messages:write_private |
Write notes only agents see, delete one's own notes (holders of the Admin role can delete any), summarize a conversation with AI. |
| Send messages as contact | messages:write_as_contact |
Post a message in the customer's name. The panel has no button for it; integrations use it through the API. |
| Create and manage conversation views | view:manage |
Save personal views, that is filtered conversation lists. |
Admin permissions
| Permission | Code | What it allows |
|---|---|---|
| Manage general settings | general_settings:manage |
Admin > Workspace > General: site name, language, timezone, default business hours, logo and other platform settings. |
| Manage notification settings | notification_settings:manage |
Admin > Notifications > Email: the mail server that sends agent emails. The page also shows a note while the EPAV mailbox is on; the mailbox itself is switched on and off in the cabinet. |
| Manage conversation statuses | status:manage |
Add, rename and delete your own statuses. |
| Manage SSO configuration | oidc:manage |
Sign-in providers, see Single sign-on (OIDC). |
| Manage tags | tags:manage |
Create, rename, delete and import tags. |
| Manage macros | macros:manage |
Create and edit macros. |
| Manage users | users:manage |
Add, edit, disable and delete agents, give them roles and teams, import agents, create API keys for them. Read the warning below. |
| Manage teams | teams:manage |
Create teams and change their settings. Who is in a team is set in the agent's card, which needs Manage users. |
| Manage automations | automations:manage |
Create and change automation rules. |
| Manage inboxes | inboxes:manage |
Channels: live chat, email, Telegram and WhatsApp, with their connections and WhatsApp templates. |
| Manage roles | roles:manage |
Create, change and delete roles. |
| Manage templates | templates:manage |
Email templates. |
| Manage reports | reports:manage |
The Reports pages and the Supervisor panel. |
| Manage business hours | business_hours:manage |
Working schedules and holidays, used by SLA policies. |
| Manage SLA policies | sla:manage |
Create and change SLA policies. |
| Manage AI features | ai:manage |
The whole Admin > AI section: providers, knowledge base, Connect your AI, editor prompts, suggestions, tools and assistants. |
| Manage help centers | help_center:manage |
Help centers, their collections and articles. |
| Manage custom attributes | custom_attributes:manage |
Extra fields for conversations and contacts. |
| Manage activity log | activity_logs:manage |
Read the activity log. |
| Manage webhooks | webhooks:manage |
Create and change outgoing webhooks. |
| Manage shared views | shared_views:manage |
Create and change views that other agents see. |
| Manage context links | context_links:manage |
Links shown next to a conversation, see Context links. |
Contact permissions
| Permission | Code | What it allows |
|---|---|---|
| View all contacts | contacts:read_all |
Open the Contacts page with every contact. |
| View contact details | contacts:read |
Open one contact's profile and search contacts. |
| Edit contact details | contacts:write |
Change a contact's details and add contacts. |
| Block contacts | contacts:block |
Block and unblock contacts. |
| Delete contacts | contacts:delete |
Delete a contact. |
| Export contact data | contacts:export |
Download the data stored about a contact. |
| Merge contacts | contacts:merge |
Merge two contacts of one person into one, see Where your data is stored. |
| View contact notes | contact_notes:read |
Read private notes on a contact. |
| Add contact notes | contact_notes:write |
Write private notes on a contact. |
| Delete contact notes | contact_notes:delete |
Remove one's own private notes on a contact. Holders of the Admin role can remove anyone's. |
Manage users is close to full access
Whoever has Manage users can give any role to any agent, the Admin role included, and that includes their own account. In one step they can grant themselves every other permission. Treat Manage users as admin access and give it only to people you trust with everything.
Creating a role
- Go to Admin > Teammates > Roles and press New role.
- Enter a Name (2 to 50 characters) and a Description (2 to 300 characters). Both are required.
- Under Set permissions for this role, tick what the role may do. A role needs at least one permission.
- Press Create.
Giving a role to an agent
Open the agent under Admin > Teammates > Agents and pick the role in Roles, next to any roles they already have. Then press Save.
When changes take effect
Changes to a role and to an agent's roles apply at once: the next action of the agent is checked against the new permissions. An agent who is signed in sees new or removed menu items after reloading the page.
Example: a team lead
To let a team lead watch the queue without making them an admin, create a role with the same permissions as Agent plus Manage reports. The lead then sees the Supervisor icon and the Reports pages, and still has no access to settings.
Built-in service accounts
Your site also has built-in service accounts and roles that EPAV Desk uses to run it; do not edit or delete them.