Overview
Create tenant roles that grant agents only the modules and actions required for their responsibilities.
Before You Start
- Tenant administrator or role-management permission.
- A clear list of responsibilities for each agent type.
Steps
1. Open Roles
Choose Roles and Apps, then Roles, to review the tenant's access profiles.
2. Create a responsibility-based role
Use a name that describes the work performed, such as Sales Agent or Support Supervisor.
3. Select permissions
Enable only the modules and actions required for that role, including conversation, contact, opportunity, calendar, or settings access.
4. Assign the role
Open the agent record and apply the correct role and organization access.
5. Test the account
Confirm the agent can complete required tasks and cannot access restricted administrative functions.
Recommended Practices
- Follow least-privilege access.
- Review roles after introducing new modules or changing responsibilities.
- Remove obsolete roles only after reassigning their users.
What Happens Next
Tenant agents receive predictable access based on their job responsibilities and organization membership.
Frequently Asked Questions
Why is a module missing for an agent?
The module may be disabled by the plan, excluded from the agent's role, or unavailable for the selected organization.
Do tenant administrators require the same role permissions?
Tenant administrators have broader tenant control, while agent access is governed by assigned roles and organization membership.