Skip to content

Team & access

Everything about the humans on your account: how they get in, what each role can open, how to narrow an operator down to specific agents, channels and pipelines, how the platform decides which manager owns a handed-over chat, and what "online" means on the Lead distribution table.

In the app

Two screens under your avatar → Settings share the same team list:

Both write to the same member records — a person invited on one screen appears on the other.

At a glance

You needWhereResult
A teammate who sets their own passwordTeam & AccessAdd memberInvitation email with a link; the row shows Invited until they accept
An operator you hand credentials toOperatorsAdd operatorA generated password shown once; role is always Operator
Decide what a role can openTeam & AccessRoles & permissionsThe Access rights by role matrix
Limit one operator to some agents / channels / pipelinesOperators → open the person → Access scopeChats and leads outside the scope disappear for them
Give handed-over chats an owner automaticallyAgents → agent → SettingsHandoff ControlAutomatic manager assignmentLead gets a Manager; that manager is notified
See workload and response speed per managerOperatorsLead distribution (or Quality Control)See Analytics & Quality Control

Two ways to add people

Team & Access → Add memberOperators → Add operator
How they log inThey receive an email and set their own password on the invite page (min. 8 characters)You get a generated password in a dialog — "Copy this password now. It won't be shown again."
RoleManager by default; any role except AdminAlways Operator
Extra fieldsDepartment (free text, e.g. Sales)Full name, phone, email
LaterChange role, Deactivate, Remove, Resend / Cancel invitationReset password (the old one stops working immediately), Delete

Rules that apply to both:

  • The account owner is listed too, but has no Delete or Reset password controls, and the API refuses to modify the owner.
  • You can never act on your own row — the row menu is hidden for yourself.
  • Invitations expire after 7 days. Expired and cancelled invitations stay in the list as history; Resend invitation issues a fresh link.
  • If the email already has a MyChatBot account elsewhere, accepting fails with "this email already has an account on the platform; invite a different email, or have them delete their existing account first."
  • If the invitation email could not be sent, the invitation still exists — resend it from the row menu.

Roles

Role (as shown)Stored asOne-line description in the app
AdminadminFull access
Sales Leadsales_leadTeam access
ManagermanagerOwn data only
OperatormoderatorOwn data only
AnalystanalystReports access

The account owner is treated as Admin everywhere. Admin cannot be granted through an invitation.

The permission matrix

Team & AccessRoles & permissionsAccess rights by role. Seven permissions, five roles. Legend: Allowed, Denied, Unavailable (a dash — not editable).

Defaults:

PermissionAdminSales LeadManagerOperatorAnalyst
View all leads — access to leads across the whole team
Own leads only — access only to own leads
Edit deals — create and edit deals
Analytics access — view reports and analytics
Finance access — view financial data
Products / warehouse access — view and edit products
Team management — add and manage team members

What the matrix does and does not do:

  • The Admin column and the Team management row are fixed. Admin always has everything; Team management can only ever be held by Admins. Those cells render as Unavailable.
  • Only two permissions are enforced by the API today: Analytics access and Team management. The other five carry an amber API enforcement coming soon badge — "API access is not restricted by this permission yet. Some permissions already affect navigation." They hide sidebar items (see below) but do not yet block direct API calls.
  • View all leads has one very concrete effect: it removes the member's Access scope entirely (see Access scope).
  • A saved matrix can take up to a minute to apply — permissions are cached per server for 60 seconds and the app re-reads them every 60 seconds.
  • Editing the matrix requires the Admin role, not a permission — so an Admin cannot lock themselves out of the screen that would undo a mistake.

What each role sees in the sidebar

Sidebar itemWho sees it
Platform Wizard, Agents, Knowledge, Catalog, Integrations, Channels, AutomationsAdmins only
OrdersEdit deals — and only once an Orders integration is connected
Active chats, Leads, TasksView all leads or Own leads only
OutreachEdit deals
Analytics, Quality ControlAnalytics access
SubscriptionFinance access
NotificationsEveryone

Where a permission is listed, the permission decides — the role is irrelevant. This is why a Manager (Analytics access on by default) sees Analytics while an Operator does not, although both are "Own data only".

Who can manage the team

CapabilityWho
Open Team & Access and read the member listAdmins and Sales Leads
Invite, change roles, deactivate, removeTeam management (Admins)
Edit the matrix, read the Access change logTeam management (Admins)
Open Operators, edit Access scope, read Lead distributionAdmins

A Sales Lead therefore sees who is on the team but cannot change anything, and does not see the Roles & permissions or Access change log tabs.

The member list

Columns: Member, Role, Department, UniTalk SIP line, Status (Active / Inactive), State (Active / Invited). Filters by search (name, email, role), role, department and status; Export team downloads a CSV (Member, Role, Department, Status).

Row actions (Actions menu):

ActionWhat it does
Change roleRole and Department. For Managers and Operators, when a UniTalk channel exists, also the UniTalk SIP line"Outbound calls from this manager use the selected SIP line. Leave as channel default to use the channel's default line."
Deactivate / ActivateAn inactive member is rejected by every API call (they cannot use the app) but keeps their row. Leads assigned to them stay assigned — reassign by hand, or let automatic assignment move them on the next handoff
RemoveDeletes the member and disables their login
Resend invitation / Cancel invitationOnly on Invited rows

Access change log

Team & AccessAccess change log: Date, Changed by, Action, Details. Actions recorded: Invitation sent (email and role), Role changed (before → after), Permissions updated (permission, role, granted or not), Member deactivated, Member removed. Visible with Team management only.

Access scope: what an operator can see

Open Operators, select the person, and use Access scope"Choose which AI agents, per-agent channels, and pipelines this operator can see. Leave agents or pipelines empty to grant access to all." The scope has three independent parts:

PartEmpty meansNotes
AI agents this operator can seeAll AI agentsThe operator only gets chats handled by these agents
Channels of the selected agentPer agent: All channels for this agent, All channels (including ones connected later), or Selected channels only. A channel that is switched off shows an off suffix
Pipelines this operator can seeEvery pipeline"A pipeline created after this save will not be visible until an admin re-saves." When nothing is picked by hand, the Linked pipelines panel shows the pipelines derived from the selected agents' Lead Management settings

How the scope is applied:

  • Admins and the owner are never scoped. Every other role is scoped as soon as a scope is saved.
  • View all leads lifts the scope. Granting that permission to the member's role makes the saved scope inert; revoke the permission and the scope applies again.
  • "Leave empty" means everything — except inside a channel list. An agent with an empty Selected channels only list means no channels of that agent, so the operator sees nothing from it. Pick All channels for this agent if that is what you meant.
  • Leads are a union. A lead is visible if it sits in one of the operator's pipelines or has a chat on one of their agents.
  • Chat filters are clamped, not pre-filled. The Assistants and Pipeline filters on Active chats only offer what the scope allows; they do not show the scope itself.
  • Live updates can lag for pipeline-only scopes. A new-message event carries only the agent, so a scope that restricts by pipeline alone cannot be evaluated in real time — such chats appear on the next list refresh, not instantly.
  • Saving is two-step: agents and pipelines save first, channel grants second. If the second step fails you get "Agents and pipelines saved. Channel access could not be saved yet: …" — fix and save again.

Scope is a visibility filter, not a permission

Access scope hides chats and leads. It does not stop an operator who can open a chat from doing anything the chat allows — Mark as spam, Clear chat history, editing the client card. See Chats → Who can see and do what.

Automatic manager assignment

Configured per agent: Agents → agent → SettingsHandoff ControlAutomatic manager assignment.

SettingMeaning
Assign a manager when a chat is handed overOff by default. "When a conversation is handed to a human, the lead is assigned to a manager automatically and that manager is notified in the bell, by email, and in the operator Telegram group."
How to choose the managerBy workload — fewest active leads among managers who are currently available; ties go round in turn. In turn (random) — round-robin across every available manager, ignoring workload and presence
Who can be assignedA checklist of the team. Empty = "any active team member can be assigned. Access Scope always applies: a manager is never given a conversation they cannot see."

What "handed over" means here: the same events that put a chat into Operator mode — the agent's own handoff, an operator's reply under implicit handoff or the stop word, or the AI switch in the chat header.

Rules worth knowing before you rely on it:

  • Sticky. A lead that already has a Manager keeps them; a repeat escalation re-notifies the owner instead of reassigning. Only a removed or deactivated owner gets replaced.
  • The person who did the handoff wins. If a teammate flips the AI switch off in the app, the lead is assigned to them, even if they are outside the pool or offline. A handoff detected from a reply sent in the messenger's own app (Telegram, Instagram…) cannot identify the person, so it falls through to the pool — and if the operator cannot be identified at all, the lead is left unassigned rather than handed to a stranger.
  • Eligible means: active member, accepted invitation, in the pool (if one is set), and whose Access scope allows both the chat's agent/channel and the lead's pipeline.
  • By workload prefers people who are Online or Away but still assigns when everyone is offline — an out-of-hours escalation still gets an owner.
  • Two channels escalating at once for the same lead result in one owner; the second escalation notifies that owner.
  • Assignment is best-effort and asynchronous: it never blocks or fails the handoff itself.
  • The notification legs — bell, email, Telegram group — are independent. A missing email or Flight Control group skips that leg only. A repeat escalation to the same manager is quiet for 15 minutes; a fresh assignment always notifies. See Notifications.

Presence: Online, Away, Busy, Offline

The Availability column on Lead distribution and the By workload picker use the same rule:

  • The app sends a heartbeat every 45 seconds while a tab is open and visible (Admins, the owner and Operators only).
  • Anyone whose last heartbeat is older than about 2 minutes shows Offline, whatever their stored status.
  • The app only ever reports Online. Away and Busy exist in the data model but there is no control to set them.

So the badge is at most a couple of minutes behind reality, and a member who closes the app is Offline within two minutes.

Use cases

  • Sales team with a supervisor — invite reps as Manager, the supervisor as Sales Lead (sees everyone's leads, cannot touch the team), keep Admin for the owner.
  • Outsourced first-line operators — add them on Operators, set an Access scope to the support agent only with All channels (including ones connected later), and leave pipelines empty.
  • Two brands, two pipelines — scope each operator to their brand's pipeline; By workload assignment then only ever picks someone who can see the lead.
  • Analyst with no inbox — role Analyst: Analytics and Quality Control only, no chats.

Test it

  1. Team & AccessAdd member with a test email, role Manager. The row shows Invited; open the link from the email and set a password. The row flips to Active, and the change log shows Invitation sent.
  2. Sign in as that member: the sidebar shows Active chats, Leads, Tasks, Analytics, Notifications — and not Agents, Channels or Subscription.
  3. In the matrix, turn Analytics access off for Manager and Save permissions. Within a minute the member's Analytics item disappears.
  4. On Operators, open the member, set Access scope to one agent with Selected channels only and one channel; save. As the member, confirm only that channel's chats are listed and the Channels filter offers nothing else.
  5. Enable Assign a manager when a chat is handed over on the agent, add the member to Who can be assigned, then have the agent hand a test chat over. The lead's Manager is filled, the member gets a bell notification, and Lead distribution counts one Active lead for them.
  6. Deactivate the member: their next request fails, the lead still shows them as Manager, and the next handoff on that lead reassigns it.

See also