Roles and Permissions
Build roles that control what teammates can do and which customer records they can access.
Roles let you match careCycle access to the way your team actually works. Permissions control what someone can do. Data Filters control which customer records they can work with.
You manage roles from Settings > Organization > Users, Invites & Roles > Roles.
How Access Works
careCycle combines two kinds of access control:
- Permissions control features and actions, such as viewing customers, transferring calls, cancelling appointments, or editing campaigns.
- Data Filters limit records by NPN, so an agent can work only their own book or a manager can work the books of the NPNs assigned to them.
Both checks are enforced on the server. A user needs the action permission and access to the target record.
Built-In Roles
| Role | Typical use | Default data scope |
|---|---|---|
| Owner | Agency principal | Full organization |
| Admin | Operations administrator | Full organization |
| Manager | Team or downline manager | Managed NPNs and directly assigned customers |
| CSR | Service team | Full organization |
| Agent | Producer or call agent | Own NPN and directly assigned customers |
Built-in roles are maintained by careCycle. Create a custom role when a team needs a different combination.
Create A Custom Role
- Open Settings > Organization > Users, Invites & Roles.
- Open Roles.
- Select Create Custom Role.
- Enter a name and description.
- Optionally start from a built-in template.
- Choose permissions by feature area.
- Configure Data Filters if the role should see only part of the book.
- Select Create Role.
- Assign the role to members from the Users tab.
Custom roles do not continue inheriting from their template. A template copies its current settings into the new role, which you can then customize.
Permission Areas
The permission editor groups options into six feature areas.
CRM
Customers
| Option | What it enables |
|---|---|
| View | View customer lists and customer details within the role's Data Filters |
| Create | Create customer records |
| Edit | Update customer fields |
| Assign | Assign or reassign customers to team members |
| Delete | Soft-delete customers so they disappear from normal workflows while history is retained |
| Import | Import a book of business |
| Export | Export customer data |
Customer Delete is intentionally high risk. It is granted to built-in Owner and Admin roles by default, not to built-in Agent, CSR, or Manager roles.
Customer Policies
| Option | What it enables |
|---|---|
| View | View policy lists and details |
| Create | Add policies |
| Edit | Update policies |
| Delete | Soft-delete policies |
Customer Contact Info
View reveals unredacted phone numbers, email addresses, and other protected contact information. Without it, applicable contact details are redacted.
Attachments
| Option | What it enables |
|---|---|
| View | View customer and policy documents |
| Upload | Upload documents |
| Update | Replace or update attachment details |
| Delete | Delete attachments |
Notes
Notes are currently part of baseline Inbox access for active members. The Notes permission family remains available for forward compatibility as note access is made more granular.
Customer Automations
View, edit, or delete organization-wide customer automation rules.
Calling
Softphone
| Option | What it enables |
|---|---|
| Use | Make, receive, recover, and disposition calls |
| Transfer | Transfer an active call; also enables Use |
| Listen | Silently listen to a live call |
| Barge | Join a live call and speak; also enables Listen |
Listen and Barge do not automatically grant Wallboard access.
Calls
| Option | What it enables |
|---|---|
| View | View call history, details, and recordings in the user's data scope |
| Export | Export calls and download protected recordings |
Call Forms
| Option | What it enables |
|---|---|
| View | View available call-form definitions |
| Edit | Design and configure call forms |
| Submit | Save the customer, policy, and custom-field entries represented by the form during a call |
Submit does not allow unrestricted customer or policy changes. It applies only the fields included in the resolved call form.
Softphone Routing
| Option | What it enables |
|---|---|
| View | View routing configurations |
| Edit | Change routing agents, groups, and routing behavior |
Phone Numbers
| Option | What it enables |
|---|---|
| View | View phone numbers and assignments |
| Manage | Procure, assign, enable, disable, and configure numbers |
Live Ops
Wallboard
| Option | What it enables |
|---|---|
| View | View live calls, queues, staffing, and routing status |
| Export | Export wallboard and productivity reports |
Wallboard View is read-only. Status and routing changes have separate permissions.
Status Overrides
| Option | What it enables |
|---|---|
| Agent | Change another online agent between Available and Busy |
| Campaign | Temporarily take an agent on or off air for one campaign |
Campaign status override does not remove the agent from the campaign's routing pool and does not affect other campaigns.
Routing Overrides
| Option | What it enables |
|---|---|
| Source Enablement | Temporarily pause routing for one campaign-source path |
| Agent Source | Temporarily block one agent from one campaign-source path |
These are temporary operational controls. They do not change the source's canonical campaign assignment.
Admin Dashboard
View opens organization-wide dashboard reporting instead of the personal agent dashboard.
Campaigns
Campaigns
| Option | What it enables |
|---|---|
| View | View campaigns and campaign details |
| Edit | Create and modify core campaign configuration |
Campaign export is not a separate permission. Pulse workflow export is managed under Pulse Workflows.
Pulse Workflows
| Option | What it enables |
|---|---|
| View | View Pulse workflow definitions |
| Edit | Build and update workflows |
| Export | Download workflow JSON |
Campaign Enrollment
Manage adds customers to campaigns and manages enrollment lifecycle actions, without automatically granting full campaign editing.
Sources
| Option | What it enables |
|---|---|
| View | View source definitions and campaign assignments |
| Edit | Create and update sources and assignments |
| Delete | Delete eligible sources |
Some source-management screens also require the corresponding Campaign permission because assignments connect the two features.
Campaign Automations
View, edit, or delete campaign automation rules.
Work
Appointments
| Option | What it enables |
|---|---|
| View | View appointment lists, details, and activity |
| Create | Preview availability and book appointments |
| Edit | Reschedule, cancel, complete, or mark appointments as no-show |
| Assign | Assign, reassign, or unassign appointments |
Unavailable actions stay visible but disabled where useful, so users can see what requires additional access.
Appointment Configuration
| Option | What it enables |
|---|---|
| View | View reusable appointment configurations |
| Create | Create or duplicate configurations |
| Edit | Edit configuration, routing, availability, and workflows |
| Delete | Delete configurations that are not in use |
Tasks
| Option | What it enables |
|---|---|
| View | View tasks and task tags |
| Edit | Create and update tasks and tags |
| Delete | Delete tasks and tags |
Task Automations
View, edit, or delete task automation rules.
Inquiries
| Option | What it enables |
|---|---|
| View | View inquiries |
| Resolve | Work and resolve inquiry workflows |
| Assign | Assign inquiries to team members |
| Export | Export inquiry data |
Ask
| Option | What it enables |
|---|---|
| View | Use Ask careCycle and saved reports |
| Export | Export generated report tables |
Admin
Billing
| Option | What it enables |
|---|---|
| View | View billing, usage, and subscription details |
| Edit | Change supported billing settings |
Developer Settings
| Option | What it enables |
|---|---|
| View | View API keys, webhooks, and organization integrations |
| Edit | Create, rotate, update, and revoke supported developer resources |
Organization
| Option | What it enables |
|---|---|
| View | View organization settings |
| Update | Change organization settings |
| Delete | Perform supported destructive organization actions |
Members
| Option | What it enables |
|---|---|
| View | View the organization member-management area |
| Create | Add supported member records |
| Update | Change member roles and access |
| Delete | Remove members |
Invitations
| Option | What it enables |
|---|---|
| Create | Invite or resend invitations |
| Cancel | Revoke pending invitations |
Access Control
| Option | What it enables |
|---|---|
| Read | View custom roles |
| Create | Create custom roles |
| Update | Edit custom roles |
| Delete | Delete unassigned custom roles |
Assigned custom roles cannot be renamed or deleted until members are reassigned.
Data Filters
Data Filters determine which records a role can see after a permission allows the feature.
| Filter | Meaning |
|---|---|
| Own NPN | The member sees records for their own NPN and directly assigned customers where applicable |
| Managed NPNs | The member sees records for the NPNs configured on their user account and direct assignments where applicable |
Filters are available for:
- Customers
- Calls
- Policies
- Attachments
After assigning a Managed NPN role, open the member's action menu and choose Configure Access to select the NPNs they manage.
Removing a resource's View permission also removes its Data Filter because a scope without feature access has no effect.
Permission Dependencies
careCycle automatically adds prerequisites in several cases:
- Most Edit, Delete, Export, and Manage actions also enable View.
- Softphone Transfer also enables Use.
- Softphone Barge also enables Listen.
The selected count includes implied permissions.
Recommended Role Design
Start With The Job, Not The Person
Create roles such as:
- Licensed Agent
- Customer Service Representative
- Team Lead
- Call Supervisor
- Billing Administrator
Avoid one-off roles named after a specific person.
Grant The Smallest Useful Set
Start with the actions required for the job. Add permissions after a real need is identified instead of enabling every feature in advance.
Separate Read From Operational Control
Examples:
- Wallboard View does not grant status overrides.
- Listen does not grant Barge.
- Appointment View does not grant Edit.
- Call Form View does not grant Submit or Edit.
Use Data Filters For Book Segmentation
Do not create a different feature role for every downline when the only difference is record scope. Reuse the role and configure member-specific Managed NPNs.
Review High-Risk Permissions
Review these carefully:
- Delete Customers
- Delete Policies
- Export customer or call data
- View Customer Contact Info
- Listen or Barge into calls
- Status and routing overrides
- Developer Settings Edit
- Access Control Create, Update, or Delete
Changes And Propagation
Permission changes normally appear quickly, but an already open browser may take up to approximately one minute to refresh effective access. Refresh the page if a role change does not appear immediately.
When a user's access is removed:
- Navigation updates after permissions refresh.
- Disabled controls prevent new actions.
- The server still rejects unauthorized requests immediately after its short authorization cache refreshes.
FAQs
Why can a user see a feature but not save changes?
They may have View without the matching action permission. Check Edit, Submit, Manage, Assign, or the other specific operation.
Why can a user not see records they expect?
Check the role's Data Filters and the NPNs configured on the member. Also check whether the customer is directly assigned to the member.
Why can a user view Wallboard but not change agent status?
Add the appropriate Status Override permission. Wallboard View is intentionally read-only.
Why can a user view calls but not download a recording?
Call export and protected recording downloads require Calls Export.
Why can a user view call forms but not save entries during a call?
Form design requires Call Forms Edit. Saving the fields represented by the form during a call requires Call Forms Submit.
Why has a permission change not appeared yet?
Wait briefly or refresh the application. If it persists, verify the member is assigned to the intended role and active organization.