Give a staff member different rights on different accounts
Follow this guide to set the four permissions independently in each account column so a user can reply in one account and view-only in another. The guide then takes you through the correct route, the checks to complete before making changes, the workflow in order, and the evidence to review afterwards.
Where to goAdmin Area → WhatsApp → Access Control
Before you start
- Verify the module is active and select the intended WhatsApp account before changing any operational record.
- Use an account with the stated native CRM capability and per-account access.
- Test with controlled customer/contact data before relying on live verification, email or CRM automation.
What you’ll accomplish
Set the four permissions independently in each account column so a user can reply in one account and view-only in another. These instructions follow the supplied r20.5 controller, model, view, installer, connector and automation flow.
Follow these steps
- Go to Admin Area → WhatsApp → Access Control.
- Select the relevant record or setting.
- Follow the supported controls described below.
- Save or confirm once.
- Check the result.
Fields and options to review
Native capabilitiesView, Manage standard replies, Audit Trail
Per-account permissionsView, Reply, Convert, Manage
Staff rowsactive CRM staff
Account columnsactive, non-deleted WhatsApp accounts
Rules the system enforces
- Reply, Convert or Manage implies View when the matrix is saved.
- Administrators can configure accounts and access, but must still be selected in the matrix to use an Inbox.
- Standard Replies also requires the native Manage standard replies capability unless the user is an administrator.
- Set the four permissions independently in each account column so a user can reply in one account and view-only in another.
How to confirm it worked
- The requested action completes without a permission, validation, connector or native CRM error.
- The selected account or conversation shows the expected state without changing another account’s data.
- Where the action creates evidence, confirm the message, native record, verification event, portal history or audit entry is present.
Security, privacy and troubleshooting checks
- Never expose connector tokens, loopback ports, authentication directories or raw customer verification replies.
- Use the supported Connections, Access Control, Settings and Audit Trail pages rather than editing runtime or database records directly.
- If the expected control is missing, verify both native capability and per-account permission before treating it as an installation fault.
Continue with related guidance
Was this guide useful?Your response is stored only in this browser.
