← Documentation
Panel manual · Organization · 7 min

Roles & Permissions

Create least-privilege roles with view and manage access per module.

01

Purpose and location

Create least-privilege roles with view and manage access per module.

Open Organization → Roles & Permissions. The available controls depend on the active edition, module entitlement, role and tenant scope.

RelayPBX roles and permissions editor with a highlighted selected role
The selected role is clearly highlighted while view and manage permissions are edited.
02

Before you start

Use a tenant-scoped administrator unless the task genuinely requires platform access. Create plans, locations and roles before assigning them to people or endpoints.

Capture the current value or export the affected records before a bulk or routing change. This gives the operator a precise comparison point and makes a supported transaction undo easier to assess.

03

Step-by-step workflow

Complete the steps in order. Do not combine an initial configuration with unrelated cleanup; small, attributable changes are easier to test and reverse.

  • Start from the closest built-in role.
  • Grant View before Manage.
  • Test the role with a non-production user.
  • Keep platform and security operations restricted.
04

Field reference

Use the reference below while completing the form. Fields hidden by edition, module entitlement or role are intentionally unavailable to the signed-in user.

Role name
Customer-visible role label.
View
Read-only module access.
Manage
Create, edit and delete access where supported.
Scope
Tenant or location boundary applied to the assignment.
05

Acceptance checks

A saved record is only the beginning of validation. Run every relevant check below and retain the call-session ID, time and result when telephony is involved.

  • Assign the role to a test user and verify both allowed and denied pages.
  • Confirm manage actions remain hidden when only View is granted.
  • Verify tenant and location boundaries with records from two different scopes.
06

Common mistakes and safe recovery

If a check fails, stop adding changes. Restore the previous value or use a supported transaction undo, regenerate PBX configuration, then repeat the smallest failing test.

  • Never test a new custom role using the only platform-owner account.
  • Permissions control the interface and API; a hidden menu item alone is not an authorization boundary.
07

What to include in a support case

Provide the tenant, module and object name, local time with timezone, expected result, observed result and the most recent successful state. For a call problem, include the logical call-session ID and the redacted SIP/SDP text diagnostic before requesting PCAP.

Never paste passwords, private keys, raw license payloads or unredacted customer media into a ticket. Use the one-time diagnostic grant and attachment controls when support requests additional evidence.