Access and permissions

Which permission each Omnichannel screen needs, who may see and change what, and the rules that keep people from approving their own work.

On this page (15)

Permissions by screen

ScreenMenuPermission needed
Unified InboxOmnichannel > Inbox > Unified Inboxomni.inbox.view
My ConversationsOmnichannel > Inbox > My Conversationsomni.inbox.view
UnassignedOmnichannel > Inbox > Unassignedomni.inbox.view
WaitingOmnichannel > Inbox > Waitingomni.inbox.view
MentionsOmnichannel > Inbox > Mentionsomni.inbox.view
StarredOmnichannel > Inbox > Starredomni.inbox.view
ArchivedOmnichannel > Inbox > Archivedomni.inbox.view
SpamOmnichannel > Inbox > Spamomni.inbox.view
Support TicketsOmnichannel > Inbox > Support Ticketsomni.inbox.view (list); omni.resolve (status changes)
Conversation workspaceInbox > open a conversation (/omnichannel/inbox/<id>)omni.inbox.view to open; omni.reply / omni.assign / omni.resolve / omni.lead.create / omni.opportunity.create / omni.quotation.create / omni.ai.use per action
Social LeadsOmnichannel > Leads > Social Leadsomni.inbox.view
Lead Ads (lead forms)Omnichannel > Leads > Lead Adsomni.inbox.view (list), omni.configure (save)
Lead InboxOmnichannel > Leads > Lead Inboxomni.inbox.view (list), omni.lead.create (add / convert / reject)
QualificationOmnichannel > Leads > Qualificationomni.inbox.view
Lead SourcesOmnichannel > Leads > Lead Sourcesomni.inbox.view (list), omni.configure (add)
Conversion RulesOmnichannel > Leads > Conversion Rulesomni.inbox.view (read), omni.configure (save)
Social AccountsOmnichannel > Social > Accountsomni.social.view
Posts + Post composerOmnichannel > Social > Postsomni.social.view; create/edit omni.social.create; approve omni.social.approve; publish/schedule omni.social.publish
CalendarOmnichannel > Social > Calendaromni.social.view
CommentsOmnichannel > Social > Commentsomni.social.view (list); omni.reply (actions); omni.lead.create (Create Lead)
MentionsOmnichannel > Social > Mentionsomni.social.view
EngagementOmnichannel > Social > Engagementomni.social.view
Media LibraryOmnichannel > Social > Media Libraryomni.social.view; omni.social.create to change
CampaignsOmnichannel > Campaigns > Campaignsmarketing.campaign.view
Ad AccountsOmnichannel > Campaigns > Ad Accountsmarketing.campaign.view
AudiencesOmnichannel > Campaigns > Audiencesmarketing.audience.view
Lead CampaignsOmnichannel > Campaigns > Lead Campaignsmarketing.campaign.view
CreativesOmnichannel > Campaigns > Creativesmarketing.campaign.view
Conversion TrackingOmnichannel > Campaigns > Conversion Trackingmarketing.analytics.view
WhatsApp ConversationsOmnichannel > WhatsApp > Conversationsomni.inbox.view
WhatsApp TemplatesOmnichannel > WhatsApp > Templatesomni.inbox.view (list), omni.whatsapp.template (changes)
BroadcastsOmnichannel > WhatsApp > Broadcastsomni.inbox.view (list), omni.broadcast (changes / send)
FlowsOmnichannel > WhatsApp > Flowsomni.inbox.view (list), omni.whatsapp.template (save)
Business NumbersOmnichannel > WhatsApp > Business Numbersomni.inbox.view
CallsOmnichannel > WhatsApp > Callsomni.inbox.view; omni.reply (log)
CatalogOmnichannel > WhatsApp > Catalogomni.inbox.view (list), omni.configure (add / remove / sync)
Content CalendarOmnichannel > Content > Content Calendaromni.social.view
DraftsOmnichannel > Content > Draftsomni.social.view
Media Library (Content)Omnichannel > Content > Media Libraryomni.social.view
Content TemplatesOmnichannel > Content > TemplatesMenu omni.social.view; server needs omni.configure
ApprovalsOmnichannel > Content > Approvalsomni.social.view; omni.social.approve to act
Brand AssetsOmnichannel > Content > Brand Assetsomni.social.view
AI Content StudioOmnichannel > Content > AI Content Studioomni.ai.use
Automation RulesOmnichannel > Automation > Rulesmarketing.automation.view
Customer JourneysOmnichannel > Automation > Customer Journeysmarketing.automation.view
ChatbotsOmnichannel > Automation > ChatbotsMenu omni.inbox.view; list needs omni.configure; save needs omni.configure + omni.automation.edit
AI Agents (AI Settings)Omnichannel > Automation > AI AgentsMenu omni.inbox.view; screen needs omni.configure
TriggersOmnichannel > Automation > Triggersmarketing.automation.view
Scheduled ActionsOmnichannel > Automation > Scheduled Actionsmarketing.automation.view
Omnichannel DashboardOmnichannel > Analytics > Omnichannel Dashboardomni.analytics.view
Lead AnalyticsOmnichannel > Analytics > Lead Analyticsomni.analytics.view
Social AnalyticsOmnichannel > Analytics > Social Analyticsomni.analytics.view
Campaign ROIOmnichannel > Analytics > Campaign ROImarketing.analytics.view
Agent PerformanceOmnichannel > Analytics > Agent Performanceomni.analytics.view
Conversion FunnelOmnichannel > Analytics > Conversion Funnelomni.analytics.view
Response SLAOmnichannel > Analytics > Response SLAomni.analytics.view
AttributionOmnichannel > Analytics > Attributionmarketing.analytics.view
Channel DashboardOmnichannel > Analytics > Channel Dashboardomni.analytics.view

Inbox

RuleWhat the system does
omni.inbox.view neededMenus not shown; API refused 'You do not have permission for this action.'
Data scope without omni.inbox.allSara sees her own, her teams' and unassigned conversations only; opening Omar's conversation by URL -> 'Conversation not found.'; supervisor with omni.inbox.all sees all

Conversation

RuleWhat the system does
omni.reply needed to writeComposer and Quick Actions disabled; POST reply/note -> refused
omni.assign needed to assign / transferAssign dialog -> refused; More > Take conversation works (needs only omni.reply)
omni.resolve for resolve / archive / spam / blockResolve / Archive / Mark as spam / Block refused

Conversion

RuleWhat the system does
Lead / opportunity / quotation rightsMatching Quick Action disabled; API refused; quotation/order also need the user's own Sales rights

AI Assistant

RuleWhat the system does
omni.ai.use and AI CANNOT listAssistant calls refused; the CANNOT list (approve discount, confirm high-value order, post accounting, issue refund, change credit, delete records) can never be granted - not in the options and stripped on save

Contact panel

RuleWhat the system does
Receivables only for finance-capable usersOutstanding row hidden

Files

RuleWhat the system does
Attachment download is company-boundGET .../workspaces/<company B>/omnichannel/files/<id> as a B user -> 'Record not found.'; images open inline, other files download with nosniff + sandbox CSP

Webhook

RuleWhat the system does
Live Meta account requires a valid X-Hub-Signature-256POST to the callback with no / wrong signature -> 403 'Signature check failed.'; correct HMAC-SHA256 of the raw body -> 200
Live account without a secret refuses everythingAny POST -> 403 'Signature check failed.'
Subscription handshakeGET callback ?hub.mode=subscribe&hub.verify_token=<token>&hub.challenge=123 -> '123' and webhook status ok; wrong token -> 403 'Verification failed.'
Unknown / inactive / app-off keyEvery POST/GET -> 404 'Not found.'
Rotate webhook addressOld callback URL returns 404; new one works; audit omni.account.rotated

Audit

RuleWhat the system does
Every send and action is auditedAdministration > Audit shows omni.message.sent / omni.note.added / omni.conversation.assign ... with the user

Social

RuleWhat the system does
omni.social.create to write, omni.social.approve to approve, omni.social.publish to publishCreate/edit/media need .create; Approve/Reject need .approve; Publish/Schedule/Unschedule/Unpublish need .publish; others refused 'You do not have permission for this action.'
Author never approves own postApprove refused 'The author cannot approve their own post.'

WhatsApp

RuleWhat the system does
omni.whatsapp.template for templates and flowsCreate / submit / clone / archive templates and save flows refused; list readable
omni.broadcast (sensitive) to send broadcastsNew / Send / Schedule / Cancel refused
Marketing template needs opt-in in the chat tooSend Template refused 'Consent: <reason>. Marketing templates need the contact's opt-in.'
Without Marketing, marketing messages are not sentBroadcast with a marketing template: every recipient skipped 'Install the Marketing app to record consent before sending marketing messages'; utility templates still go

Leads

RuleWhat the system does
omni.lead.create to add / convert / reject; omni.configure for forms, sources, rulesAgent can convert; agent cannot save lead forms or conversion rules

Analytics

RuleWhat the system does
omni.analytics.viewAnalytics menu hidden; GET .../analytics/dashboard refused

Catalog

RuleWhat the system does
omni.configure for catalog changesAdd / remove / sync refused; Send Catalog in a chat still works (omni.reply)

Media

RuleWhat the system does
Public media link needs the file hashIts public link works; same link with a wrong / shorter (< 16 chars) k -> 404 'Not found.'