Purpose and location
Create least-privilege roles with view and manage access per module.
Open Organization → Roles & Permissions. The available controls depend on the active edition, module entitlement, role and tenant scope.

Before you start
Use a tenant-scoped administrator unless the task genuinely requires platform access. Create plans, locations and roles before assigning them to people or endpoints.
Capture the current value or export the affected records before a bulk or routing change. This gives the operator a precise comparison point and makes a supported transaction undo easier to assess.
Step-by-step workflow
Complete the steps in order. Do not combine an initial configuration with unrelated cleanup; small, attributable changes are easier to test and reverse.
- Start from the closest built-in role.
- Grant View before Manage.
- Test the role with a non-production user.
- Keep platform and security operations restricted.
Field reference
Use the reference below while completing the form. Fields hidden by edition, module entitlement or role are intentionally unavailable to the signed-in user.
- Role name
- Customer-visible role label.
- View
- Read-only module access.
- Manage
- Create, edit and delete access where supported.
- Scope
- Tenant or location boundary applied to the assignment.
Acceptance checks
A saved record is only the beginning of validation. Run every relevant check below and retain the call-session ID, time and result when telephony is involved.
- Assign the role to a test user and verify both allowed and denied pages.
- Confirm manage actions remain hidden when only View is granted.
- Verify tenant and location boundaries with records from two different scopes.
Common mistakes and safe recovery
If a check fails, stop adding changes. Restore the previous value or use a supported transaction undo, regenerate PBX configuration, then repeat the smallest failing test.
- Never test a new custom role using the only platform-owner account.
- Permissions control the interface and API; a hidden menu item alone is not an authorization boundary.
What to include in a support case
Provide the tenant, module and object name, local time with timezone, expected result, observed result and the most recent successful state. For a call problem, include the logical call-session ID and the redacted SIP/SDP text diagnostic before requesting PCAP.
Never paste passwords, private keys, raw license payloads or unredacted customer media into a ticket. Use the one-time diagnostic grant and attachment controls when support requests additional evidence.