ChakraHQChakraHQ

Role Access Guide

A reference guide to default feature access across the three platform roles; User, Manager, and Admin for the Sales CRM and Chat platform.

Role Access Guide

This guide has two sections:

  • Section 1: User vs Manager — day-to-day CRM activity access.
  • Section 2: Manager vs Admin — admin configuration and platform setup access.

Section 1: User vs Manager

A comparison of default feature access between the User and Manager roles for day-to-day CRM and Chat activities.

Feature Access Comparison

Feature Group

User

Manager

Access to Chats & Leads

◐ Assigned only — can see and work only on chats/leads assigned to them

✓ All records — full visibility across all leads/chats by default

Bulk Download

✕ Not available

✓ Available

Bulk Upload

✓ Available

✓ Available

Lead Field Editing

✓ View & edit — all fields, for their accessible leads

✓ View & edit — all fields, for their accessible leads

State / Status Changes

✓ Available

✓ Available

"Assigned To" Field

✓ Editable — for their accessible leads/processes

✓ Editable — for their accessible leads/processes

Template Creation — WhatsApp

✓ Enabled

✓ Enabled

Template Creation — Email & Others

✕ Not enabled

✓ Enabled

Campaigns Module

✕ Not supported

✓ Enabled

Admin Configuration — User & Team Management, Reports, Campaigns

✕ No access

✓ Access (covered in Section 2)

Platform Setup — Tasks, Forms, Automations (LCR, Allocation, etc.)

✕ No access

✓ Access (covered in Section 2)

Key Takeaway

Users are scoped to their own work: assigned leads/chats only, with the ability to edit fields, update statuses, and reassign records within that scope, and send WhatsApp templates. They cannot bulk-download data, run campaigns, create non-WhatsApp templates, or touch any admin configuration — reports, team management, forms, tasks, or automation setup.

Managers get everything a User gets, plus workspace-wide visibility into all leads/chats, bulk download, campaigns, and the full set of message template types — while Admin Configuration itself (user/team setup, report building, task/form/automation configuration) remains a separate layer, covered in Section 2 below.

A Note on Customization

The behaviors above reflect default role settings. All of these permissions can be adjusted through Role-Based Access Control (RBAC), so a workspace can tighten or loosen access for either role to match its own operating model.


Section 2: Manager vs Admin

A plain-language guide to what Managers and Admins can each do in Admin Configuration settings.

The Core Difference

Admin is the platform's full-control role, with access to every configuration area — from day-to-day operations to backend platform setup, security, billing, and integrations.

Manager is a scoped, operational role. Managers can run their team's day-to-day work — managing people, reports, templates, forms, and process workflows — but cannot touch the platform's structural configuration: billing, security, integrations, messaging-channel setup, or AI configuration.

In short: Manager access sits entirely within Admin access — anything a Manager can do, an Admin can also do, but not the other way around. Manager permissions are additive and operational; Admin permissions extend further into platform governance, risk, and irreversible changes.

What Managers Can Do

Team & User Management — Managers can onboard and manage the people on their team: creating and removing user accounts, assigning or changing roles, and enabling or disabling login access as people join, move, or leave.

Reports & Dashboards — Managers have full control over reporting: they can create, edit, clone, and delete data tables and chart dashboards, and pull standard reports such as attendance summaries, to track team performance.

Message Templates & Notifications — Managers can create, update, and delete message templates and notification configurations, letting them manage how the team communicates with contacts and how internal alerts are set up.

Forms & Process Allocation — Managers can manage intake and workflow forms (setting a form as the default resource form or removing one) and can update or delete process allocators (routing logic that assigns work), but cannot create new process templates or state/task mappings from scratch.

Lifecycle & Custom Process Actions — Managers can create, edit, and remove lifecycle actions and custom process actions, giving them control over the automated actions that fire at different stages of a contact's or ticket's journey.

App Installs & Procedure Mapping — Managers can view installed apps and manage procedure-to-role mappings, letting them see what's connected and adjust which roles handle which procedures, without managing the underlying integrations themselves.

External APIs — Managers have limited API-related access, restricted to removing external API connections rather than creating or configuring them.

What ONLY Admins Can Do

The following areas are restricted to Admin only. These generally involve platform-wide configuration, financial or security risk, or irreversible changes — the kinds of actions that affect the entire workspace rather than a single team.

Billing, Payments & Subscription — Managing checkout sessions, coupon codes, subscription upgrades, and cancellations.

Security, Domains & API Access — Configuring authentication providers, security rules, sandboxes, custom domains, and creating or revoking API keys.

WhatsApp & Messaging Channel Setup — Connecting or disconnecting WhatsApp Business accounts and phone numbers, managing WhatsApp groups, and reviewing channel-level API and webhook logs.

Plugins & Integrations — Installing, updating, or configuring plugins and third-party integrations, including setting default plugins per category and viewing plugin logs.

AI Features & Content Sources — Enabling AI features for the team and managing the content sources AI tools draw from.

Web App Builder — Creating, editing, publishing, or unpublishing custom web apps built on the platform.

Calling & Shift Configuration — Setting up call allocators, managing shift configurations, and configuring calling infrastructure such as Exotel WebRTC apps.

Campaigns & Outreach — Creating or removing campaign triggers and auto-dial campaigns used for automated outreach.

Contacts & Data Attributes — Deleting contacts and custom data attributes at the account level.

Chatbot & Chat Widget — Managing chatbot templates and chat widget triggers shown to website visitors.

Email Deliverability — Reviewing, creating, and removing bounced-email records that affect sender reputation and deliverability.

Team, Navigation & Platform Assets — Managing team/partner hierarchies, navigation structure, public assets, scripts, and free trial activation.

Feature & Access Rule Configuration — Defining feature configurations and resource access rules that govern what different roles can see or do platform-wide.

Deeper Process & State Configuration — Creating new process templates, defining state-to-task mappings, and deleting process entries, states, or state tasks outright — the structural definitions behind workflows, as opposed to day-to-day allocation, which Managers can adjust.

How to Think About Assigning These Roles

  • Default to Manager for team leads. If someone needs to manage people, reports, templates, forms, or workflows for their team, Manager access covers it without exposing platform-wide settings.
  • Reserve Admin for platform owners. Assign Admin only to those who need to configure integrations, security, billing, or messaging infrastructure — actions that affect the whole workspace and are harder to reverse.
  • When in doubt, start narrow. Since Manager access is a subset of Admin, it's safer to start someone as Manager and upgrade to Admin later than to over-grant Admin access upfront.

Putting It All Together

The three roles form a clean hierarchy of access:

User → Manager → Admin

  • User: works within their assigned leads/chats — no admin or platform configuration access.
  • Manager: everything a User can do, plus workspace-wide record visibility, campaigns, and day-to-day admin configuration (users, reports, templates, forms, workflows).
  • Admin: everything a Manager can do, plus platform-wide governance — billing, security, integrations, messaging-channel setup, and AI configuration.

Each role is a strict superset of the one before it, and all defaults described in this guide can be fine-tuned through Role-Based Access Control (RBAC) to match your workspace's needs.

On this page