Skip to main content

System permissions reference

The System permissions tab answers one question for every feature in Teloring: may this role reach it, and may it change anything there?

The System permissions tab, grouped into Customers, Workspace, Tools, Settings, Agents and teams, and Billing

How the grid works

Each row is a feature. Each column is an action. Tick a box to grant it.

ElementWhat it does
Group headingSix groups — Customers, Workspace, Tools, Settings, Agents & teams, Billing. Purely for orientation; grouping grants nothing.
Row labelThe feature, matching the sidebar wording so you can find it in the product. Some rows carry a one-line hint underneath explaining a non-obvious action.
Column headerRead, Create, Update, Delete. Click a header to tick or untick that action for every row in the group at once — one click to grant a whole column, a second to clear it.
CheckboxThe permission itself.
dashThis action does not exist for this feature. There is nothing to grant. Hovering says Not applicable to this item.
Indented rowsObjects that live inside a customer, shown nested under Customers.

How the four actions work

ActionWhat it grants
ReadReach the feature and look at it. Nothing can be changed.
CreateAdd a new item.
UpdateChange an existing item.
DeleteRemove an item.

Create, Update and Delete each include Read automatically. You cannot create a customer you are not allowed to see, so the moment you tick any write action, Read switches on and locks — it turns a lighter shade and cannot be unticked while a write action is set.

A row where Read is locked on because Update is ticked

To release Read, untick the write actions first.

Why a lock rather than a hidden box

The alternative — quietly storing "Update but not Read" and then ignoring it — would mean the grid on screen did not match what the role actually does. The lock keeps the two identical: what you see ticked is exactly what is stored.

Read-only roles are the useful ones

An auditor, an accountant, a consultant, a stakeholder who wants dashboards — all of them want Read on a few things and nothing else. Tick the Read column, save, done.


Customers

The CRM. The first row is the customer record itself; the indented rows below are the objects inside a customer.

FeatureReadCreateUpdateDelete
CustomersOpen the Customers page and a customer recordAdd a customerEdit a customer, and edit the fields of any customer object in the field editorDelete a customer
JourneySee the customer's timeline
ConversationsSee the customer's conversations tab
CallsSee the customer's calls tab
DocumentsSee the customer's signed documents tab
Contacts, Service Calls, Deals, Tasks, Notes, and any object you createSee records of that typeAdd a recordEdit a recordDelete a record

Why some rows are Read-only

Journey, Conversations, Calls and Documents are written by Teloring itself. A journey entry is a record of something that already happened; a call log is a record of a call. There is nothing to create or edit from the customer page, so only Read exists.

Your own object types appear here automatically

Every CRM object type in your account gets its own row with all four actions, including ones you designed yourself in the field editor. Create a Contracts object today and it is on this grid immediately, with its own label and icon — no waiting, no separate setup.

Disabled object types are not listed, since there is nothing to permit.

"Update" on Customers also grants the field editor

Customers → Update covers two things: editing a customer record, and changing the shape of your CRM — adding an object type, adding or removing fields, reordering them.

That is how the product is built: both are "changing the customer model". If you want somebody to edit customer data but never restructure the CRM, that separation does not exist today. Give Update on the individual object rows and leave Customers → Update off — they can then edit records of those objects without reaching the designer.


Workspace

FeatureReadCreateUpdateDelete
ViewsOpen Views and run a saved viewBuild a new viewEdit an existing viewDelete a view
My Ring (inboxes)Open My Ring and see inbox configurationConnect a new inboxChange inbox settingsDisconnect an inbox
AnalyticsOpen Analytics, read boards and reports, exportCreate a report or boardEdit a report, board or tabDelete a report or a whole board
Conversation attributesSee the attributes panel in a conversation and on a resolved one, and open the Settings pageFill values in on a conversation, and add or edit attributes in SettingsRemove an attribute from the account's design
Conversation attributes has no Create

An attribute is part of one account-wide design, not a separate item — so adding one is editing that design, and it needs Update. See Conversation Attributes.

Update covers both filling in and designing, the same way Customers → Update also covers the field editor. If you want front-line agents to record a reason and an outcome without being able to restructure the form, that separation does not exist today; in practice the Settings page is not somewhere agents go.

Delete is only ever "remove an attribute from the design". It never deletes the values already stored on conversations — those are kept, and re-creating the attribute with the same API ID brings them back into view.

My Ring is inbox setup, not inbox access

My Ring governs the configuration page — connecting a WhatsApp number, editing email settings, disconnecting a channel.

Whether an agent can work in an inbox is a completely separate thing, on the Channel permissions tab. A front-line agent normally has no My Ring access at all while working in every inbox all day.

One consequence worth knowing: an agent with My Ring → Read sees every inbox in the account listed there, including ones they cannot work in. If that matters for you, do not grant it.


Tools

FeatureReadCreateUpdateDelete
StudioOpen Studio, read flows, versions and run historyCreate a flow or a scheduleEdit, publish, pause, resume or test a flowDelete a flow or schedule
AI WorldOpen AI World and see which features are onSwitch AI features on and off
Knowledge baseOpen it, browse sources, ask questionsCreate a knowledge base, upload a sourceRefresh a sourceDelete a knowledge base or a source
Quick repliesOpen quick replies and use them in a conversationCreate a quick reply or categoryEdit oneDelete one
Forms builderOpen Forms, read forms and submissions, exportCreate or duplicate a formEdit a form, publish it, upload an imageDelete a form
Document signatureOpen it and read documentsCreate a document and send it for signingEdit a documentDelete a document
Files warehouseOpen it, view and download filesDelete files
AchievementsOpen the Achievements page and see progressCollect a completed achievement

The unusual ones

AI World has no items to create or delete — it is a board of switches. Update is what lets somebody flip them. With Read only, an agent sees which AI features are on but cannot change any.

Achievements works the same way. Read shows the page and progress; Update is what lets somebody press Collect and add the reward credits to the account.

Files warehouse has no Create, because files arrive by being uploaded elsewhere — a conversation attachment, a knowledge base source, a form image. Read includes downloading. Delete is the one that matters, and it is the permission that also allows deleting somebody else's upload and using Delete all.

Quick replies: personal versus shared

Writing a personal quick reply only you can see is self-service — anybody with Read can do it.

Create, Update and Delete govern the account-wide ones every agent sees. The default Agent role has all four, so front-line agents can build the shared library. If you would rather they only used it, drop the role to Read and keep the write actions for supervisors.


Settings

Each settings tab is a separate row, because they are genuinely different concerns — reading the business address is not reading the API keys. A role that grants none of them does not see Settings in the sidebar at all; a role that grants one lands directly on that tab.

FeatureReadCreateUpdateDelete
General infoOpen the tabChange business name, logo, language, timezone, currency, country
Business hoursOpen the tabAdd a schedule or holiday calendarEdit oneDelete one
Security & loginOpen the tab, see active sessionsChange IP allowlist, enforced 2FA, idle timeout; force-sign-out a session
APIOpen the tab and see the key listIssue a new API keyRevoke a key
Data & privacyOpen the tabRequest a data exportDelete the entire account
Data & privacy → Delete deletes the workspace

This is the single most destructive permission in Teloring. It is what allows the Danger Zone → Delete account action.

The default roles give it to Owner only. Keep it that way unless you have a specific reason.

API has no Update

An API key cannot be edited — a key is a secret, and changing it would mean issuing a new one. So the actions are Create (issue) and Delete (revoke).

Webhook subscriptions are governed by the same row, since they are part of the same developer surface.


Agents & teams

FeatureReadCreateUpdateDelete
AgentsOpen the Agents directory and search itInvite a new agent, create an AI AgentEdit any agent — role, language, 2FA, department, notes, their voice access; reset another agent's password; move another agent's email; resend an invitation; deactivateDelete an agent profile
TeamsOpen Teams and see the team listCreate a teamEdit a team — name, members, rulesDelete a team
Roles & permissionsOpen this page and read every roleCreate a roleEdit a roleDelete a role
Audit logOpen the audit log and read it

Things that are always self-service

Two actions on the Agents page never need a permission, because they concern the agent themselves:

  • resetting their own password;
  • changing their own sign-in email.

Both travel through a one-time link sent to their own inbox. Agents → Update is what extends those actions to other people.

Roles & permissions is the master key

Anybody who can create or edit a role can give themselves — or anybody else — every other permission in Teloring, including billing and account deletion. That is not a flaw; it is what editing a role means.

Treat it exactly like an administrator password. The default roles give Create, Update and Delete to Owner only, and Read to Team Leader so a manager can see the structure without changing it.

Voice access lives under Agents

Switching Teloring browser calling on for a specific person is part of editing that agent, so it needs Agents → Update. The account-wide voice switch and voice inbox configuration are under My Ring.


Billing

FeatureReadCreateUpdateDelete
CreditsSee the credit balance, the header credit badge, and transaction history
SubscriptionSee the current plan, seats and usage metersChange plan
Credit cardsSee stored cards — brand and last four digits onlyAdd a cardUpdate a card's expiryRemove a card
Usage pricingSee the per-action price list

The Billing entry disappears from the sidebar entirely when a role grants none of these. If a role grants some, only those tabs appear, and opening Billing lands on one the agent can read.

The credit badge in the header

The monthly and top-up credit figures in the top bar are shown only to roles with Credits → Read. Roles without it never see the account's balance.


What the default roles grant

R Read · C Create · U Update · D Delete · no access

FeatureOwnerTeam LeaderMarketingAgentViewer
CustomersR C U DR C U DR C UR C UR
JourneyRRRRR
Conversations (in customer)RRRRR
CallsRRRRR
DocumentsRRRRR
Contacts / Service Calls / Deals / Tasks / NotesR C U DR C U DR C UR C UR
ViewsR C U DR C U DR C U DRR
My Ring (inboxes)R C U DR URR
AnalyticsR C U DR C U DR C U DR
Conversation attributesR U DR U DR UR UR
StudioR C U DR C U DR C U D
AI WorldR UR UR U
Knowledge baseR C U DR C U DR C U DRR
Quick repliesR C U DR C U DR C U DR C U DR
Forms builderR C U DR C U DR C U DR
Document signatureR C U DR C U DRR CR
Files warehouseR DR DRRR
AchievementsR UR UR UR UR
Settings → General infoR URRR
Settings → Business hoursR C U DR C U DR
Settings → Security & loginR UR
Settings → APIR C DR
Settings → Data & privacyR C D
AgentsR C U DRRRR
TeamsR C U DR C U DRRR
Roles & permissionsR C U DR
Audit logRR
Billing → CreditsR
Billing → SubscriptionR U
Billing → Credit cardsR C U D
Billing → Usage pricingR

Owner is shown fully ticked for reference. In practice it is not a stored grid at all — it is permanent full access that cannot be edited.

New permissions are not added to existing roles

This table is what a newly created account gets. A permission added to Teloring after your account was created is not ticked on your existing roles — nothing is ever granted behind your back. Conversation attributes is the most recent example: until you tick it, only Owner reaches the feature. Open a role, tick the row, and save.

Reading the table

  • Team Leader is a full support manager with no financial or administrative reach. It can see the API key list and the security settings but change neither, so a manager can answer "is 2FA enforced?" without being able to rotate a key.
  • Marketing builds and measures. It can restructure Studio, forms and analytics but cannot connect an inbox, manage agents or reach billing.
  • Agent is deliberately narrow outside conversations: customers, quick replies, the knowledge base to look things up, and sending documents for signature. No Studio, no analytics, no settings. It does get Conversation attributes → Update, because recording a reason and an outcome is part of handling a conversation.
  • Viewer is Read almost everywhere and write nowhere — and, crucially, no conversations at all (see Channel permissions).