Skip to main content

Roles & Permissions

Review built-in user roles, create custom roles, and configure read and manage permissions across Ender Turing features. This article is automatically maintained (roles-and-permissions).

Overview

Roles control what each user can see and do in Ender Turing. Every user account is assigned one or more roles, and each role grants a set of read and manage permissions across platform features such as Conversations, Dashboards, Chats, Agents, Trainings, EnderDrive, and System Configuration.

Ender Turing ships with built-in roles for common job functions (Admin, Manager, Analyst, Reviewer, Agent, Agent with Team Dashboards, Agent Lead). When the built-in set is not enough, users with the Manage Users permission can create custom roles, either from scratch or based on an existing role.

How It Works

Accessing Roles & Permissions

  1. Open Settings from the main navigation.

  2. Select Users & Agents.

  3. Open the Roles & Permissions tab.

The tab shows a table of all roles with their Name, the number of Permissions assigned, and the count of Users currently using each role.

To open this tab, your role must include the Manage Users permission. Without it, the tab is hidden.

Built-in Roles

Built-in roles are marked as protected. They appear in the role list with an eye icon instead of a pencil icon, and opening one shows the permissions matrix in read-only mode. You cannot rename, edit, or delete a built-in role.

Typical built-in roles include:

  • Admin — full access across the platform.

  • Manager — broad operational access with limited settings access.

  • Analyst — analytics and dispute access.

  • Reviewer — review and scoring access.

  • Agent — access only to the agent's own data.

  • Agent with Team Dashboards — a standalone Agent role with all regular Agent access plus Team Dashboard, Funnel, Charts, and Topics views.

  • Agent Lead — access to data for the team the agent belongs to.

If you need a different mix of permissions, create a custom role.

Choosing Between the Two Agent Roles

Agent access comes in two alternatives. Assign one of them — the second is not an add-on:

  • Agent — the linked agent's own data, including their personal My Dashboard page. Team-wide Dashboard views, Charts, Topics, and Funnels are not available.

  • Agent with Team Dashboards — everything the Agent role grants, plus the team Dashboard views (Quality & Performance, Tags, Overall), Charts, Topics, and Funnels.

Because the second role already contains the full Agent permission set, a linked agent needs only that one role. Neither role includes the Reviewers Leaderboard, C-Level Boards, or Discovery; create a custom role if an agent needs those.

Existing user accounts are never reassigned automatically. If agents in your organization should see team dashboards, assign them Agent with Team Dashboards from the Manage Users tab, or build a custom role with the permission mix you need.

Creating a Custom Role

You can create a role from scratch or by copying an existing one as a starting point.

From an existing role:

  1. On the Roles & Permissions tab, click Create Role.

  2. In the Create role dialog, the Create from existing tab is selected by default. Click any role in the list to use it as a template.

  3. The role editor opens with the source role's permissions pre-selected. Enter a new Role name in the top bar.

  4. Adjust the permissions checkboxes as needed.

  5. Click Save in the top bar.

From a blank role:

  1. On the Roles & Permissions tab, click Create Role.

  2. In the Create role dialog, switch to the Create from blank tab.

  3. Enter a Role name and select the permissions you want to grant.

  4. Click Save in the top bar.

A role name is required. The save button stays disabled until the form is valid.

The Permissions Matrix

Permissions are organized into feature groups. For each row, you can grant up to six checkboxes:

Column

Meaning

Permissions to read · All

View all items of this type across the organization.

Permissions to read · Team

View items belonging to the user's team(s).

Permissions to read · Own

View only items the user owns or is linked to.

Permissions to manage · All

Create, edit, or delete items of this type across the organization.

Permissions to manage · Team

Manage items belonging to the user's team(s).

Permissions to manage · Own

Manage only items the user owns.

Some checkboxes are intentionally not available for certain features. When a permission does not apply (for example, Manage · Team on a feature that has no team-level management), the checkbox is shown but disabled.

The available feature groups include:

  • Dashboard — Base, Funnels, Charts, C-Level Boards.

  • Conversations — Base access plus separate switches for Metadata, Transcripts, Scores, Comments, Initiate Dispute, and Void Dispute.

  • EnderGPT Chats — Chats (with both All and Own read scopes), Shared Chats, Scheduled Chats, and Scheduled Chat Results.

  • Agents / Teams — Agents and Teams management.

  • TODO lists — TODO tasks.

  • Trainings — Training plans, skills, and quizzes.

  • Playlists — Playlists.

  • Analytics Configuration — Tags; Topics / Discovery / Compliance; Enders / Automation Management.

  • Ender Drive — Ender Drive folders and Media Files.

  • System Configuration — User Management, System Configuration, Marketplace, Integrations, ASR Configuration.

Implicit Permission Rules

The permissions form applies a few rules automatically so that role configurations stay consistent:

  • Scope inheritance — within the same action (read or manage), enabling All automatically enables Team and Own, and enabling Team automatically enables Own. This applies to every row that exposes those scopes.

  • Linked rows — some rows are wired to copy their value from another row or column. For example, the Conversations sub-rows (Metadata, Transcripts, Scores, Comments) follow the read scope of the Conversations Base row, and several rows (such as the dispute switches, Analytics Configuration, User Management, Marketplace, Integrations, and ASR Configuration) tie their read column to their own manage column, so enabling manage there also enables read. Most other rows — for example Dashboard, Conversations Base, Agents, Trainings, Playlists, and Ender Drive — keep their read and manage columns independent, so you can enable manage without read or vice versa.

If you toggle a checkbox and another one updates by itself, that is one of these rules in action. If a checkbox stays disabled when you would expect it to follow, the row simply does not expose that combination.

Editing or Deleting a Custom Role

  1. On the Roles & Permissions tab, click the pencil icon on a custom role row.

  2. Update the role name in the top bar or change permissions in the matrix.

  3. Click Save to apply changes, Reset (the close icon) to discard unsaved changes, or Delete (the trash icon) to remove the role.

Both Reset and Delete open a confirmation dialog before any change is applied.

Deleting a role removes it from the list. Users who had only that role will lose the associated permissions, so reassign affected users to another role before deletion.

Assigning a Role to a User

Roles are assigned to users from the Manage Users tab in the same Users & Agents section. Open a user's edit screen and add or remove roles from the Roles field. A user can have multiple roles; the resulting permissions are the union of all assigned roles.

Limits and Caveats

  • Built-in roles are read-only. To customize one, open it as a template via Create from existing and save as a new role.

  • The Manage Users permission is required to view, create, edit, or delete roles. Without it, the Roles & Permissions tab is hidden.

  • A role must have a name before it can be saved.

  • Some permission combinations are disabled by design — for example, a feature that only has organization-wide management will show the Team and Own manage checkboxes as disabled.

  • The user count shown on the role list reflects users currently assigned to the role. Deleting a role does not delete those users; they keep their other roles, if any.

Did this answer your question?