--- title: "Role Profiles & RBAC Permissions" description: "Enterprise Role-Based Access Control (RBAC), administrative permission matrices, granular telephony action privileges, and resource visibility scoping." --- ## 📖 Introduction The **Role Profiles** module provides granular, enterprise-grade Role-Based Access Control (RBAC) specifically tailored for the Switchboard console. It decouples user accounts from hardcoded privileges, enabling administrators to define distinct operational roles such as **Operators**, **Supervisors**, **Call Center Agents**, and **System Administrators**. Each Role Profile defines two interconnected layers of authorization: 1. **Administrative Permissions**: Access to console configuration, theming, layout management, and user provisioning. 2. **Switchboard Telephony Privileges**: Granular authorization governing live call interception (Listen, Whisper, Barge), transfer capabilities, and resource visibility (Extensions, Queues, Conferences, Parking Lots, Trunks). ![Role Profiles Management](/screenshots/apps/switchboard/role-profiles.png) --- ## 🛡️ Default System Roles The platform ships with pre-configured role profiles that serve as baselines: | Role Name | Scope | Default Permissions | Intended Audience | | :--- | :--- | :--- | :--- | | **Administrator** | System (Protected) | `FULL` across all administrative modules and unrestricted telephony privileges. | PBX System Admins & Telecom Engineers. | | **Supervisor** | Enterprise Default | `FULL` on active calls, eavesdrop, whisper, and barge; `READ` on layouts and queues. | Call Center Team Leads & QA Managers. | | **Agent / Operator** | Standard Tenant | `NONE` on admin panels; `FULL` on My Settings; restricted to transfers and basic call handling. | Front-desk receptionists, triage operators, agents. | > [!NOTE] > System-designated roles (marked with a blue shield badge) cannot be deleted to prevent enterprise lockouts. Custom roles can be created, edited, duplicated, and assigned freely. --- ## 🎛️ Administrative Permissions Matrix Within the **General Settings** tab of a Role Profile, administrators configure access levels (`FULL`, `READ`, `NONE`) across 12 distinct functional modules: | Permission Identifier | Module Label | Description & Security Impact | | :--- | :--- | :--- | | `manageRoles` | **Manage Roles** | Authority to create, modify, or delete Role Profiles and grant privileges. | | `manageUsers` | **Manage Users** | Authority to provision Switchboard user accounts and assign role associations. | | `manageLayouts` | **Manage Global Layouts** | Authority to publish and overwrite system-wide widget layouts. | | `createLayouts` | **Create Layouts** | Permission for operators to generate personal, customized console layouts. | | `editLayouts` | **Edit Layouts** | Permission to reposition, resize, and reconfigure widgets on existing layouts. | | `addWidgets` | **Add Widgets** | Authority to add new telemetry cards from the Widget Catalog. | | `accessSettings` | **WebRTC / ICE Settings** | Permission to modify global STUN, TURN, and ICE gathering timeouts. | | `accessMySettings` | **Access My Settings** | Grants users the ability to manage their personal profile, ringtones, and sounds. | | `manageAppearance` | **Manage Appearance** | Authority to customize color themes, dark mode variants, and UI scale. | | `manageBranding` | **Manage Branding** | Authority to upload custom logos, favicons, and login welcome screens. | | `managePauseCauses` | **Manage Pause Causes** | Authority to create and reorder agent break cause profiles. | | `manageCallFlags` | **Manage Flag Profiles** | Authority to configure color-coded visual call classification flags. | --- ## 🎧 Switchboard Privileges & Telephony Authorization The **Switchboard Privileges** tab regulates real-time telephony capabilities. It prevents unauthorized operators from listening to sensitive conversations or interfering with executive extensions. ```mermaid graph LR User[Operator / Supervisor] --> Role[Role Profile] Role --> ResourceScope[Resource Scope: All vs Specific Items] Role --> ActionScope[Action Scope: Transfers, Eavesdrop, Whisper, Barge] ResourceScope --> FS[Telephony Event Socket (ESL) Control] ActionScope --> FS ``` ### 1. Resource Visibility Scoping For each telephony object, administrators can set access to **All Resources** or restrict to **Specific Items**: - **Extensions**: Restrict operator visibility to specific departments (e.g., only Sales extensions `1000-1099`). - **Call Queues**: Limit monitoring to specific queues (e.g., `Queue-Support` only). - **Parking Lots**: Assign dedicated parking lots per team. - **Conference Rooms**: Scoped visibility for executive boardrooms versus public audio bridges. - **SIP Trunks**: Limit trunk telemetry to authorized network supervisors. ### 2. Live Action Privileges Controls the real-time operational verbs that can be executed from call widgets: | Telephony Action | Action Key | Functional Impact | | :--- | :--- | :--- | | **Originate Call** | `call` | Ability to trigger outbound calls directly from the console interface. | | **Blind Transfer** | `blindTransfer` | Immediately redirects an active call to a new destination without announcement. | | **Attended Transfer** | `attendedTransfer` | Initiates a warm consultation call prior to completing the transfer. | | **Eavesdrop (Listen)** | `spy` | Silently joins an active audio channel via Telephony Server `eavesdrop` in listen-only mode. | | **Whisper (Coach)** | `whisper` | Speaks into an agent's ear channel without customer audio bleed. | | **Barge-In (Conference)**| `barge` | Unmutes bidirectional audio, turning an active call into a 3-way conference. | | **Call Intercom / Paging**| `intercom` | Triggers auto-answer speakerphone paging on supported SIP desk phones. | | **Queue Call Pickup** | `stealQueueCall` | Intercepts a high-priority customer directly out of an ACD queue. | --- ## 🔗 Profile Associations Each Role Profile can link directly to auxiliary profiles: - **Default Flag Profile**: Assigns standard visual flags (e.g., `VIP`, `Escalated`, `Urgent`) for calls processed by users in this role. - **Default Pause Cause Profile**: Automatically provisions allowed break codes for call center agents assigned to this role. - **SSO Default Role**: Automatically assigns newly authenticated Single Sign-On users into this role profile upon their first login.