Roles and permissions
What each role (owner, manager, staff and read-only) can see and do, how to invite the team and how to work with several projects.
Updated:
Each person joins a business (a project) with a role. The role decides which screens they see and what they can change. The server enforces it: hiding a button in the dashboard is not the only barrier.
The four roles
| Role | For whom | What they do |
|---|---|---|
Owner (owner) | Whoever administers the account | Everything, including API keys, the team and channels |
Manager (manager) | Supervisors | Runs the business: catalog, team, customers, bot, flows, channels and webhooks. Does not administer API keys |
Staff (staff) | Whoever serves or delivers | Sees and works on their own: their tasks and what their group can take |
Read-only (viewer) | Partners, accountants | Views Today, Work and conversations; changes nothing |
What each one sees in the dashboard
| Section | Owner | Manager | Staff | Read-only |
|---|---|---|---|---|
| Today and Work | Yes | Yes | Their own | Yes (read) |
| Conversations | Yes | Yes | Only theirs | Yes (read) |
| Catalog, Team, Customers | Yes | Yes | No | No |
| Bot and Flows | Yes | Yes | No | No |
| Settings, Channels, AI and usage | Yes | Yes | No | No |
| Webhooks | Yes | Yes | No | No |
| API keys (Developers) | Yes | No | No | No |
Staff look up customers with a minimal view: name, partially hidden phone, tags and no-shows, with a minimum number of characters and a result cap. A courier sees a delivery's exact destination only after taking it; before that they see an approximate area.
Invite the team
In Team you can invite in two ways:
- By email: for owner, manager, staff or read-only. The person accepts the invitation and creates a password.
- By contact (WhatsApp): only for operational staff, without a password. They are sent an access link to their agenda.
You associate a staff person with one or more resources (their agenda, their vehicle): that defines which tasks they see and which they can take. You can change a role or remove someone at any time; their sessions and their Telegram stop working immediately.
Several projects
An account can have several projects (businesses or branches), each with its own team, agenda, channels and data, fully isolated. The number of projects depends on the plan.
- With more than one project, the dashboard's project selector lets you switch between them.
- Only the account owner can create a new project, from a template by industry (barbershop, aesthetics, clinic, restaurant or deliveries).
- Your role can be different in each project.
Platform support
When you need help, the Wagend team can enter your project temporarily:
- Always with a written reason and for at most 60 minutes.
- In read mode (sees what a manager would see, changes nothing) or assist mode (can adjust catalog, schedules and business settings).
- Never able to see or change API keys, passwords, channel secrets, billing or the team, nor send messages to your customers.
- Every entry and exit is logged and the owner sees them in the business activity, with who, in which mode and why.
API keys and permissions
API keys have no role: they have scopes (narrow permissions, such as slots:read or bookings:write) and only the owner creates them. See Authentication.