careCycle
Run your team

Roles and Permissions

Build roles that control what teammates can do and which customer records they can access.

Roles let you match careCycle access to the way your team actually works. Permissions control what someone can do. Data Filters control which customer records they can work with.

You manage roles from Settings > Organization > Users, Invites & Roles > Roles.

How Access Works

careCycle combines two kinds of access control:

  • Permissions control features and actions, such as viewing customers, transferring calls, cancelling appointments, or editing campaigns.
  • Data Filters limit records by NPN, so an agent can work only their own book or a manager can work the books of the NPNs assigned to them.

Both checks are enforced on the server. A user needs the action permission and access to the target record.

Built-In Roles

RoleTypical useDefault data scope
OwnerAgency principalFull organization
AdminOperations administratorFull organization
ManagerTeam or downline managerManaged NPNs and directly assigned customers
CSRService teamFull organization
AgentProducer or call agentOwn NPN and directly assigned customers

Built-in roles are maintained by careCycle. Create a custom role when a team needs a different combination.

Create A Custom Role

  1. Open Settings > Organization > Users, Invites & Roles.
  2. Open Roles.
  3. Select Create Custom Role.
  4. Enter a name and description.
  5. Optionally start from a built-in template.
  6. Choose permissions by feature area.
  7. Configure Data Filters if the role should see only part of the book.
  8. Select Create Role.
  9. Assign the role to members from the Users tab.

Custom roles do not continue inheriting from their template. A template copies its current settings into the new role, which you can then customize.

Permission Areas

The permission editor groups options into six feature areas.

CRM

Customers

OptionWhat it enables
ViewView customer lists and customer details within the role's Data Filters
CreateCreate customer records
EditUpdate customer fields
AssignAssign or reassign customers to team members
DeleteSoft-delete customers so they disappear from normal workflows while history is retained
ImportImport a book of business
ExportExport customer data

Customer Delete is intentionally high risk. It is granted to built-in Owner and Admin roles by default, not to built-in Agent, CSR, or Manager roles.

Customer Policies

OptionWhat it enables
ViewView policy lists and details
CreateAdd policies
EditUpdate policies
DeleteSoft-delete policies

Customer Contact Info

View reveals unredacted phone numbers, email addresses, and other protected contact information. Without it, applicable contact details are redacted.

Attachments

OptionWhat it enables
ViewView customer and policy documents
UploadUpload documents
UpdateReplace or update attachment details
DeleteDelete attachments

Notes

Notes are currently part of baseline Inbox access for active members. The Notes permission family remains available for forward compatibility as note access is made more granular.

Customer Automations

View, edit, or delete organization-wide customer automation rules.

Calling

Softphone

OptionWhat it enables
UseMake, receive, recover, and disposition calls
TransferTransfer an active call; also enables Use
ListenSilently listen to a live call
BargeJoin a live call and speak; also enables Listen

Listen and Barge do not automatically grant Wallboard access.

Calls

OptionWhat it enables
ViewView call history, details, and recordings in the user's data scope
ExportExport calls and download protected recordings

Call Forms

OptionWhat it enables
ViewView available call-form definitions
EditDesign and configure call forms
SubmitSave the customer, policy, and custom-field entries represented by the form during a call

Submit does not allow unrestricted customer or policy changes. It applies only the fields included in the resolved call form.

Softphone Routing

OptionWhat it enables
ViewView routing configurations
EditChange routing agents, groups, and routing behavior

Phone Numbers

OptionWhat it enables
ViewView phone numbers and assignments
ManageProcure, assign, enable, disable, and configure numbers

Live Ops

Wallboard

OptionWhat it enables
ViewView live calls, queues, staffing, and routing status
ExportExport wallboard and productivity reports

Wallboard View is read-only. Status and routing changes have separate permissions.

Status Overrides

OptionWhat it enables
AgentChange another online agent between Available and Busy
CampaignTemporarily take an agent on or off air for one campaign

Campaign status override does not remove the agent from the campaign's routing pool and does not affect other campaigns.

Routing Overrides

OptionWhat it enables
Source EnablementTemporarily pause routing for one campaign-source path
Agent SourceTemporarily block one agent from one campaign-source path

These are temporary operational controls. They do not change the source's canonical campaign assignment.

Admin Dashboard

View opens organization-wide dashboard reporting instead of the personal agent dashboard.

Campaigns

Campaigns

OptionWhat it enables
ViewView campaigns and campaign details
EditCreate and modify core campaign configuration

Campaign export is not a separate permission. Pulse workflow export is managed under Pulse Workflows.

Pulse Workflows

OptionWhat it enables
ViewView Pulse workflow definitions
EditBuild and update workflows
ExportDownload workflow JSON

Campaign Enrollment

Manage adds customers to campaigns and manages enrollment lifecycle actions, without automatically granting full campaign editing.

Sources

OptionWhat it enables
ViewView source definitions and campaign assignments
EditCreate and update sources and assignments
DeleteDelete eligible sources

Some source-management screens also require the corresponding Campaign permission because assignments connect the two features.

Campaign Automations

View, edit, or delete campaign automation rules.

Work

Appointments

OptionWhat it enables
ViewView appointment lists, details, and activity
CreatePreview availability and book appointments
EditReschedule, cancel, complete, or mark appointments as no-show
AssignAssign, reassign, or unassign appointments

Unavailable actions stay visible but disabled where useful, so users can see what requires additional access.

Appointment Configuration

OptionWhat it enables
ViewView reusable appointment configurations
CreateCreate or duplicate configurations
EditEdit configuration, routing, availability, and workflows
DeleteDelete configurations that are not in use

Tasks

OptionWhat it enables
ViewView tasks and task tags
EditCreate and update tasks and tags
DeleteDelete tasks and tags

Task Automations

View, edit, or delete task automation rules.

Inquiries

OptionWhat it enables
ViewView inquiries
ResolveWork and resolve inquiry workflows
AssignAssign inquiries to team members
ExportExport inquiry data

Ask

OptionWhat it enables
ViewUse Ask careCycle and saved reports
ExportExport generated report tables

Admin

Billing

OptionWhat it enables
ViewView billing, usage, and subscription details
EditChange supported billing settings

Developer Settings

OptionWhat it enables
ViewView API keys, webhooks, and organization integrations
EditCreate, rotate, update, and revoke supported developer resources

Organization

OptionWhat it enables
ViewView organization settings
UpdateChange organization settings
DeletePerform supported destructive organization actions

Members

OptionWhat it enables
ViewView the organization member-management area
CreateAdd supported member records
UpdateChange member roles and access
DeleteRemove members

Invitations

OptionWhat it enables
CreateInvite or resend invitations
CancelRevoke pending invitations

Access Control

OptionWhat it enables
ReadView custom roles
CreateCreate custom roles
UpdateEdit custom roles
DeleteDelete unassigned custom roles

Assigned custom roles cannot be renamed or deleted until members are reassigned.

Data Filters

Data Filters determine which records a role can see after a permission allows the feature.

FilterMeaning
Own NPNThe member sees records for their own NPN and directly assigned customers where applicable
Managed NPNsThe member sees records for the NPNs configured on their user account and direct assignments where applicable

Filters are available for:

  • Customers
  • Calls
  • Policies
  • Attachments

After assigning a Managed NPN role, open the member's action menu and choose Configure Access to select the NPNs they manage.

Removing a resource's View permission also removes its Data Filter because a scope without feature access has no effect.

Permission Dependencies

careCycle automatically adds prerequisites in several cases:

  • Most Edit, Delete, Export, and Manage actions also enable View.
  • Softphone Transfer also enables Use.
  • Softphone Barge also enables Listen.

The selected count includes implied permissions.

Start With The Job, Not The Person

Create roles such as:

  • Licensed Agent
  • Customer Service Representative
  • Team Lead
  • Call Supervisor
  • Billing Administrator

Avoid one-off roles named after a specific person.

Grant The Smallest Useful Set

Start with the actions required for the job. Add permissions after a real need is identified instead of enabling every feature in advance.

Separate Read From Operational Control

Examples:

  • Wallboard View does not grant status overrides.
  • Listen does not grant Barge.
  • Appointment View does not grant Edit.
  • Call Form View does not grant Submit or Edit.

Use Data Filters For Book Segmentation

Do not create a different feature role for every downline when the only difference is record scope. Reuse the role and configure member-specific Managed NPNs.

Review High-Risk Permissions

Review these carefully:

  • Delete Customers
  • Delete Policies
  • Export customer or call data
  • View Customer Contact Info
  • Listen or Barge into calls
  • Status and routing overrides
  • Developer Settings Edit
  • Access Control Create, Update, or Delete

Changes And Propagation

Permission changes normally appear quickly, but an already open browser may take up to approximately one minute to refresh effective access. Refresh the page if a role change does not appear immediately.

When a user's access is removed:

  • Navigation updates after permissions refresh.
  • Disabled controls prevent new actions.
  • The server still rejects unauthorized requests immediately after its short authorization cache refreshes.

FAQs

On this page