Overview of Custom Permission in Qontak One

Article author
Learning Center Mekari
  • Updated

Custom Permission is used to manage the access and actions that can be performed on various features in Qontak One. Each permission has a permission key that indicates a specific feature or access, as well as the type of action that can be performed, such as view, manage, delete, add, and upload.

This guide explains the structure of a permission key, the types of actions available, and how to read and understand the permission applied to a specific feature. Use this guide as a reference to understand Custom Permission settings before applying them to the features you use.

A. Basic Access Management Concepts 

Before understanding Custom Permission, there are three terms you need to understand: user, role, and permission. These three terms are interconnected in determining the access each user has in Qontak One. 

User

A user is a person who uses or logs in to Qontak One. Each user has information such as a name and email address, and has one role that determines their access within the system.

Role

A role is a collection of permissions assigned a specific name according to access needs. Examples include Sales Supervisor, Night CS Agent, or Finance Viewer.

Instead of assigning permissions one by one to each user, you can configure several permissions in one role, then apply that role to the appropriate users.

A single role can be used by multiple users. Therefore, changes to the permissions in a role will apply to all users who use that role.

Permission

A permission is a specific access right or capability that a user can have. Examples include permission to view the Inbox, delete call recordings, or add contacts.

Each permission has an official name used by the system, known as a permission key. This permission key is used to identify specific access to features in Qontak One.

Based on this relationship, a user gets access through a role, while a role consists of one or more permissions. Understanding this is the foundation for understanding Custom Permission.

Custom Permission allows you to create your own role and determine the combination of permissions it contains, so you can customize access according to your needs.

Simply put, the relationship between user, role, and permission can be illustrated as follows: 

B. How to Read a Permission Key

Each permission has a special name called a permission key. This name consists of three parts separated by underscores ( _ )

For example:

  • module_feature_action
  • inbox_general_view

Each part provides different information: 

PartExampleExplanation
ModuleinboxIndicates the main feature or area where the permission is used.
FeaturegeneralIndicates the part or scope of the feature being configured. general means that the permission applies to the feature as a whole.
ActionviewIndicates the action that can be performed, such as viewing, managing, deleting, or adding.

Here are some examples of how to read a permission key: 

Permission keyMeaning
inbox_general_viewCan view all sections in the Inbox module.
inbox_general_manageCan manage all sections in the Inbox module.
inbox_scorecard_viewCan view the Scorecard feature in the Inbox module.
customers_customers_addCan add Customer data in the Customers module.
usman_roles_deleteCan delete Roles in the User Management module.
settings_integrations_viewCan view the Integrations section in the Settings module.

C. Types of Actions in a Permission 

ActionMeaningIf Access Is Not Granted
ViewAllows you to view and open pages or data. This access is for viewing only, without changing data.The page or menu cannot be opened, or a message appears stating that you do not have access.
ManageAllows you to manage data, including adding and changing data.Data may still be viewable, but buttons such as Add, Edit, or Save are unavailable.
DeleteAllows you to delete data.The Delete button is unavailable.
AddAllows you to add new data without granting access to change existing data.The Add or Create New button is unavailable.
Upload / ImportAllows you to add data from a file at once, such as importing contact data.The Upload or Import button is unavailable.
Export / DownloadAllows you to download data or files from the system, such as in Excel or CSV format.The Export or Download button is unavailable.
Profile ViewAllows you to open the detail or profile page for data.Data may still be visible in the list, but cannot be opened to view its details.

Important
Not all modules have the same types of actions.
Each module has different actions depending on the available features. For example, one module may only have View and Manage, while another may have View, Manage, Delete, and Export. If an action is not available in a module, it means that the action is not provided for that module.

View is required before using other actions.
Actions such as Manage or Delete require View access. If View is not granted, you cannot open the related page to perform the action. Therefore, make sure View is granted first.

Action names on the screen may differ, but their functions remain the same.
Some actions may be displayed with more specific names according to the feature, such as Manage recording. Although the displayed name differs, its basic function still follows the corresponding action type.

D. General View as the Main Module Access 

General View is an important permission that determines whether a module can be accessed by a user.

Permission with the pattern <module>_general_view is generally used to display the module and its menus in the sidebar. Therefore, General View does not only provide access to view a single page, but also determines whether the module can be displayed and accessed in general.

Example: inbox_general_view

This permission provides access to view the Inbox module and the menus available within it. Once the module can be accessed, other permissions can be used to configure the actions that can be performed, such as manage, delete, or export.

What happens when General View is turned on?

  • The module will appear in the sidebar.

  • Submenus within the module can be displayed if the required permissions are also turned on.

  • You can open the module and view its contents according to the access granted.

What happens when General View is turned off?

  • The module will no longer appear in the sidebar. The module menu will disappear completely from the navigation.

  • Submenus within the module will also not be displayed. If the main menu is hidden, the submenus within it cannot be accessed either, even if the permissions for those submenus are still turned on.

  • Other permissions in the module cannot be used. For example, Manage, Delete, or Export may still be listed in the settings, but cannot be used because the module cannot be accessed.

General View OnGeneral View Off
Inbox is displayed in the Sidebar along with the All Chat, My Chat, and Scorecard submenus. Inbox is not displayed in the Sidebar, so the All Chat, My Chat, and Scorecard submenus are also unavailable.

E. Data Access Levels: All access, Team only, and Ownership 

Some permissions have additional settings to determine the data that can be accessed. These settings are available as radio buttons below the relevant permission.

The data access level determines the data that can be viewed or managed, not the actions that can be performed.

Option on the ScreenExplanation
All accessCan access data from the entire company.
Team onlyCan access data owned by the team you belong to.
OwnershipCan only access data that you own.

Example of applying the View permission in the Inbox module:

  • All access: You can view all conversations in the company.
  • Team only: You can only view conversations handled by your team.
  • Ownership: You can only view conversations assigned to you.

Important
All three options use the View permission. The difference lies in the scope of data that can be accessed.

If the relevant permission is not enabled, the access level options will not be displayed.