Staff capabilities and per-account access control

Understand the two-layer permission model

Distinguish native module capabilities from the View, Reply, Convert and Manage matrix that is assigned separately for every WhatsApp account.

Audience: CRM administrators and security managersPermission: AdministratorModule v1.0.0 · 2026.07.30-r20.5
Exact navigationAdmin Area → WhatsApp → Access Control
Before you begin
  • Confirm the module is active and select the intended WhatsApp account before changing any operational record.
  • Use an account with the stated native CRM capability and per-account access.
  • Test with controlled customer/contact data before relying on live verification, email or CRM automation.

What this guide covers

Distinguish native module capabilities from the View, Reply, Convert and Manage matrix that is assigned separately for every WhatsApp account. These instructions follow the supplied r20.5 controller, model, view, installer, connector and automation flow.

Exact step-by-step process

  1. Open Admin Area → WhatsApp → Access Control.
  2. Locate the account, conversation, setting, session or evidence relevant to “Understand the two-layer permission model”.
  3. Review the displayed value or behaviour against this guide’s code-backed rules.
  4. Do not change unrelated account, CRM or connector settings while verifying the result.
  5. Confirm the expected state in the related Inbox, Connections, customer history, native CRM record or Audit Trail.

Fields, choices and supported possibilities

Native capabilitiesView, Manage standard replies, Audit Trail
Per-account permissionsView, Reply, Convert, Manage
Staff rowsactive CRM staff
Account columnsactive, non-deleted WhatsApp accounts

Code-backed validations and workflow rules

  • Reply, Convert or Manage implies View when the matrix is saved.
  • Administrators can configure accounts and access, but must still be selected in the matrix to use an Inbox.
  • Standard Replies also requires the native Manage standard replies capability unless the user is an administrator.
  • Distinguish native module capabilities from the View, Reply, Convert and Manage matrix that is assigned separately for every WhatsApp account.

Expected result and verification

  • The requested action completes without a permission, validation, connector or native CRM error.
  • The selected account or conversation shows the expected state without changing another account’s data.
  • Where the action creates evidence, confirm the message, native record, verification event, portal history or audit entry is present.

Security, privacy and troubleshooting checks

  • Never expose connector tokens, loopback ports, authentication directories or raw customer verification replies.
  • Use the supported Connections, Access Control, Settings and Audit Trail pages rather than editing runtime or database records directly.
  • If the expected control is missing, verify both native capability and per-account permission before treating it as an installation fault.