#Role Reference

7 min read
RoleAccess Level
Client AdminFull customer access across available customer surfaces
Client ManagerBroad review access, with view-only access for most operational settings
Client StaffLimited access to calls, support, read-only report schedules, and their own account

#Overview

Every AiDial portal user is assigned a role that determines what they can see and do. This page provides a quick reference for the three customer roles. For detailed information about how roles are assigned, see Roles and Permissions.

Access is enforced by the portal for each signed-in session. The browser uses your portal session, and you do not need to enter or send an API key.

Your own profile, password, multi-factor authentication, notification list, and active sessions live in the Account area at /account for all three customer roles. Open it from the account menu at the bottom of the sidebar. Settings at /settings covers organisation and project settings only.

Navigation visibility is a convenience, not the security boundary. If a direct link is outside your role, tenant, or project scope, the portal blocks access without exposing cross-tenant identifiers.

#Customer Roles

#Client Administrator

The primary administrative role for your organisation. Client administrators open Overview (dashboard), Calls, Quality, Billing, Compliance, Settings, and Support from the sidebar, and reach the status page and audit log by direct link. Within Compliance they can open every subsection: Consent, Data Retention, Evidence Trail, Caller Requests, and Reports.

They can edit the available customer-managed settings, request and download account data exports, and submit or cancel data deletion requests. Team and user management — adding, removing, changing roles, and managing another user's sessions — is handled by your AiDial partner, not by client administrators.

Sensitive-access (PII unlock) requests are permitted for this role on the portal's server-side route, but the current Calls inline review panel does not mount the unlock request form, so there is no supported in-browser way to submit one.

Recording playback and download are not currently exposed in the customer portal. Recording posture summaries may appear where a page includes compliance or data-retention context.

Multi-factor authentication: Not mandatory by role, but it may still be required by an explicit tenant or user policy.

#Client Manager

A senior role with broad visibility but limited management capabilities. Client managers see the same sidebar as client administrators — Overview, Calls, Quality, Billing, Compliance, Settings, and Support — and reach the status page and audit log by direct link. Within Compliance they can open Consent and Evidence Trail; Data Retention, Caller Requests, and Reports are Client Admin only.

Client managers review settings as read-only summaries rather than editing them. Report delivery schedules are read-only for this role and recipient addresses are masked. Data exports and data deletion requests are not shown at all. Team and user management is handled by your AiDial partner and is not available to client managers.

Sensitive-access (PII unlock) requests carry the same server-side permission as client administrators, and the same absence of an in-browser request form. Recording playback and download are not currently exposed in the customer portal.

Multi-factor authentication: Not mandatory by role, but it may still be required by an explicit tenant or user policy.

#Client Staff

A standard user role for day-to-day operational access. Client staff land on Calls after signing in and see Overview, Calls, Settings, and Support in the sidebar. They can view project-scoped calls with the caller number masked, create and review support tickets, open the status page by direct link, and manage their own profile, security, and sessions from the Account area.

Reports is the only section shown in Settings for this role, and it is read-only: schedules and delivery history can be reviewed but not saved, and recipient addresses are masked.

Client staff cannot access billing, compliance, audit logs, PII unlock, data exports, data deletion requests, recording playback/download, or operational settings such as notifications, opening hours, call limits, and transfers. Team and user management is not a customer portal feature and is handled by your AiDial partner.

Multi-factor authentication: Not mandatory by role, but it may still be required by an explicit tenant or user policy.

#Feature Access Comparison

FeatureClient AdminClient ManagerClient Staff
DashboardFullFullFull
Call log and inline reviewFullFullCaller number masked
Recording playbackNot exposedNot exposedNot exposed
Recording downloadNot exposedNot exposedNot exposed
Support ticketsCreate and reviewCreate and reviewCreate and review
System status (direct link)YesYesYes
Compliance - Consent, Evidence TrailYesYesNo
Compliance - Data Retention, Caller Requests, ReportsYesNoNo
Billing overview and invoicesYesYesNo
Billing portalYesYesNo
Team and user managementHandled by your AiDial partnerHandled by your AiDial partnerHandled by your AiDial partner
Account - profileEditEditEdit
Account - own active sessionsYesYesYes
Settings - notificationsEditView summaryNo section
Settings - reportsEditView only, recipients maskedView only, recipients masked
Settings - opening hoursEditView summaryNo section
Settings - call limitsEdit, direct linkView summaryNo section
Settings - security / IP allowlistEdit, direct linkView summaryNo section
Settings - compliance copy / collection noticeEdit, direct linkView summaryNo section
Settings - secondary useEdit, direct linkView summaryNo section
Settings - transfer settingsEdit, direct linkView summaryNo section
Settings - tenant settingsEdit, direct linkView summaryNo section
Settings - data governanceNo sectionNo sectionNo section
Settings - data exportsRequest/cancel/download, direct linkNo sectionNo section
Settings - data deletionSubmit/cancel and view, direct linkNo sectionNo section
Plan and entitlementsDetail viewSummary onlyNo access
PII unlock requestsServer-side permission, no request form in the UIServer-side permission, no request form in the UINo
Audit log (direct link)YesYesNo
MFA required by roleNo, unless explicitly requiredNo, unless explicitly requiredNo, unless explicitly required

"No section" means the server does not include that section in the Settings shell for the role. A direct ?section=... link to a section that is not included normalises to the first section your role can open, so it does not render an error state.

"Direct link" means the section is served for Client Admin but is deliberately kept out of the visible Client Admin Settings menu, which shows only Opening hours, Notifications, and Reports. Open those sections with their ?section=... link; the panel then shows a "Viewing: <Section>" caption above the menu.

Profile and Active Sessions are the exception to the normalising rule: they live in the Account area. For Client Admin, /settings?section=profile redirects to /account?section=profile; for Client Manager and Client Staff, /settings?section=profile and /settings?section=active-sessions return a not-found state.

The customer sidebar changes based on role:

  • Client Admins see Overview (dashboard), Calls, Billing, Compliance, Settings, and Support.
  • Client Managers see Overview (dashboard), Calls, Billing, Compliance, Settings, and Support.
  • Client Staff see Overview (dashboard), Calls, Settings, and Support.

All three roles also get an account menu at the bottom of the sidebar with Profile, Security, and Sign out. Profile and Security open the Account area at /account.

Status is not a sidebar item for any customer role. The status page stays reachable by direct link for every customer role — only the sidebar entry is omitted.

The Audit Log is not a sidebar item for any customer role either. Client Admins and Client Managers still have audit log access by direct link, and the Compliance area provides a related Evidence Trail view; Client Staff have no audit log access at all. Navigation visibility is a convenience, not the security boundary: the portal enforces access on every request regardless of which links are shown.

Compliance opens on Consent for both Client Admin and Client Manager. The Compliance subnav then lists only the subsections your role can open.

Team and user management is not part of the customer portal for any role; it is handled by your AiDial partner. Customer-facing consent and collection notice copy is managed through Settings - compliance copy / collection notice.