#Role Reference
| Role | Access Level |
|---|---|
| Client Admin | Full customer access across available customer surfaces |
| Client Manager | Broad review access, with view-only access for most operational settings |
| Client Staff | Limited access to calls, support, read-only report schedules, and their own account |
#Overview
Every AiDial portal user is assigned a role that determines what they can see and do. This page provides a quick reference for the three customer roles. For detailed information about how roles are assigned, see Roles and Permissions.
Access is enforced by the portal for each signed-in session. The browser uses your portal session, and you do not need to enter or send an API key.
Your own profile, password, multi-factor authentication, notification list, and active sessions live in the Account area at /account for all three customer roles. Open it from the account menu at the bottom of the sidebar. Settings at /settings covers organisation and project settings only.
Navigation visibility is a convenience, not the security boundary. If a direct link is outside your role, tenant, or project scope, the portal blocks access without exposing cross-tenant identifiers.
#Customer Roles
#Client Administrator
The primary administrative role for your organisation. Client administrators open Overview (dashboard), Calls, Billing, Compliance, Settings, and Support from the sidebar, and reach the status page and audit log by direct link. Within Compliance they can open every subsection: Consent, Data Retention, Evidence Trail, Caller Requests, and Reports.
They can edit the available customer-managed settings, request and download account data exports, and submit or cancel data deletion requests. Team and user management — adding, removing, changing roles, and managing another user's sessions — is handled by your AiDial partner, not by client administrators.
Sensitive-access (PII unlock) requests are permitted for this role on the portal's server-side route, but the current Calls inline review panel does not mount the unlock request form, so there is no supported in-browser way to submit one.
Recording playback and download are not currently exposed in the customer portal. Recording posture summaries may appear where a page includes compliance or data-retention context.
Multi-factor authentication: Not mandatory by role, but it may still be required by an explicit tenant or user policy.
#Client Manager
A senior role with broad visibility but limited management capabilities. Client managers see the same sidebar as client administrators — Overview, Calls, Billing, Compliance, Settings, and Support — and reach the status page and audit log by direct link. Within Compliance they can open Consent and Evidence Trail; Data Retention, Caller Requests, and Reports are Client Admin only.
Client managers review settings as read-only summaries rather than editing them. Report delivery schedules are read-only for this role and recipient addresses are masked. Data exports and data deletion requests are not shown at all. Team and user management is handled by your AiDial partner and is not available to client managers.
Sensitive-access (PII unlock) requests carry the same server-side permission as client administrators, and the same absence of an in-browser request form. Recording playback and download are not currently exposed in the customer portal.
Multi-factor authentication: Not mandatory by role, but it may still be required by an explicit tenant or user policy.
#Client Staff
A standard user role for day-to-day operational access. Client staff land on Calls after signing in and see Overview, Calls, Settings, and Support in the sidebar. They can view project-scoped calls with the caller number masked, create and review support tickets, open the status page by direct link, and manage their own profile, security, and sessions from the Account area.
Reports is the only section shown in Settings for this role, and it is read-only: schedules and delivery history can be reviewed but not saved, and recipient addresses are masked.
Client staff cannot access billing, compliance, audit logs, PII unlock, data exports, data deletion requests, recording playback/download, or operational settings such as notifications, opening hours, call limits, and transfers. Team and user management is not a customer portal feature and is handled by your AiDial partner.
Multi-factor authentication: Not mandatory by role, but it may still be required by an explicit tenant or user policy.
#Feature Access Comparison
| Feature | Client Admin | Client Manager | Client Staff |
|---|---|---|---|
| Dashboard | Full | Full | Full |
| Call log and inline review | Full | Full | Caller number masked |
| Recording playback | Not exposed | Not exposed | Not exposed |
| Recording download | Not exposed | Not exposed | Not exposed |
| Support tickets | Create and review | Create and review | Create and review |
| System status (direct link) | Yes | Yes | Yes |
| Compliance - Consent, Evidence Trail | Yes | Yes | No |
| Compliance - Data Retention, Caller Requests, Reports | Yes | No | No |
| Billing overview and invoices | Yes | Yes | No |
| Billing portal | Yes | Yes | No |
| Team and user management | Handled by your AiDial partner | Handled by your AiDial partner | Handled by your AiDial partner |
| Account - profile | Edit | Edit | Edit |
| Account - own active sessions | Yes | Yes | Yes |
| Settings - notifications | Edit | View summary | No section |
| Settings - reports | Edit | View only, recipients masked | View only, recipients masked |
| Settings - opening hours | Edit | View summary | No section |
| Settings - call limits | Edit, direct link | View summary | No section |
| Settings - security / IP allowlist | Edit, direct link | View summary | No section |
| Settings - compliance copy / collection notice | Edit, direct link | View summary | No section |
| Settings - secondary use | Edit, direct link | View summary | No section |
| Settings - transfer settings | Edit, direct link | View summary | No section |
| Settings - tenant settings | Edit, direct link | View summary | No section |
| Settings - data governance | No section | No section | No section |
| Settings - data exports | Request/cancel/download, direct link | No section | No section |
| Settings - data deletion | Submit/cancel and view, direct link | No section | No section |
| Plan and entitlements | Detail view | Summary only | No access |
| PII unlock requests | Server-side permission, no request form in the UI | Server-side permission, no request form in the UI | No |
| Audit log (direct link) | Yes | Yes | No |
| MFA required by role | No, unless explicitly required | No, unless explicitly required | No, unless explicitly required |
"No section" means the server does not include that section in the Settings shell for the role. A direct ?section=... link to a section that is not included normalises to the first section your role can open, so it does not render an error state.
"Direct link" means the section is served for Client Admin but is deliberately kept out of the visible Client Admin Settings menu, which shows only Opening hours, Notifications, and Reports. Open those sections with their ?section=... link; the panel then shows a "Viewing: <Section>" caption above the menu.
Profile and Active Sessions are the exception to the normalising rule: they live in the Account area. For Client Admin, /settings?section=profile redirects to /account?section=profile; for Client Manager and Client Staff, /settings?section=profile and /settings?section=active-sessions return a not-found state.
#Sidebar Differences
The customer sidebar changes based on role:
- Client Admins see Overview (dashboard), Calls, Billing, Compliance, Settings, and Support.
- Client Managers see Overview (dashboard), Calls, Billing, Compliance, Settings, and Support.
- Client Staff see Overview (dashboard), Calls, Settings, and Support.
All three roles also get an account menu at the bottom of the sidebar with Profile, Security, and Sign out. Profile and Security open the Account area at /account.
Status is not a sidebar item for any customer role. The status page stays reachable by direct link for every customer role — only the sidebar entry is omitted.
The Audit Log is not a sidebar item for any customer role either. Client Admins and Client Managers still have audit log access by direct link, and the Compliance area provides a related Evidence Trail view; Client Staff have no audit log access at all. Navigation visibility is a convenience, not the security boundary: the portal enforces access on every request regardless of which links are shown.
Compliance opens on Consent for both Client Admin and Client Manager. The Compliance subnav then lists only the subsections your role can open.
Team and user management is not part of the customer portal for any role; it is handled by your AiDial partner. Customer-facing consent and collection notice copy is managed through Settings - compliance copy / collection notice.
#Related Pages
- Roles and Permissions - detailed role descriptions
- Settings Overview - full per-role Settings section table
- Multi-Factor Authentication - MFA setup and management
- Getting Started - first-time portal orientation