Home/Help Center/Roles reference

Account, billing and security

Roles and permissions reference

Every VGraple CRM role (Owner, Admin, Supervisor, Agent, Viewer) and custom role explained: what each can see and do, who can invite whom, and what only the owner can touch.

By Chirag Darji · Updated 27 Aug 2026 · 6 min read

On this page
  1. Before you start
  2. The five system roles
  3. What each role can do
  4. Custom roles
  5. Who can manage whom
  6. How teams change what an Agent sees
  7. Choosing roles for common setups
  8. Owner-only actions
  9. Settings and options
  10. Troubleshooting
  11. Own records only
Team members in VGraple CRM with owner, admin and agent roles and their permissions

VGraple CRM uses role-based access: every teammate has one role, and the role decides which modules they see and which actions they can take. Five system roles cover most teams; custom roles let an owner shape access module by module. This reference lists what each role can do, who can manage whom, and the handful of things reserved for the owner.

Before you start

  • Roles are assigned when you invite someone under Settings, then Team, and can be changed later by an Owner or Admin.
  • Seats count against the plan: Free 1, Starter 5, Growth 15, Scale unlimited. Deactivating a member frees the seat.
  • Team membership controls which conversations an Agent sees; the role controls what they can do with them.

The five system roles

RoleSummaryTypical use
OwnerFull control: organisation settings, billing, secrets, all roles, ownership transfer, organisation deactivationThe business owner or the person who signed up
AdminInvite and manage Supervisors, Agents and Viewers; full feature access; edits settings but cannot view secretsOperations lead, agency account manager
SupervisorSees all conversations, assigns agents, views analytics; cannot change settingsTeam lead, floor manager
AgentHandles assigned and unassigned conversations; no access to settings, flows or broadcastsSales and support staff
ViewerRead-only conversations, contacts and analytics; cannot send messagesAuditor, trainee, finance

Profile settings in VGraple CRM with two-factor authentication

What each role can do

CapabilityOwnerAdminSupervisorAgentViewer
View all conversationsYesYesYesAssigned and unassigned onlyYes
Send messages, resolve, assignYesYesYesSend and resolveNo
Manage quick replies (canned responses)YesYesNoNoNo
Contacts: view, create, edit, delete, blockYesYesView, create, editView, create, editView
Leads and pipeline stagesYesYesView, editView, editView
Broadcasts: create, send, deleteYesYesNoNoNo
Flows: create, edit, toggle, deleteYesYesNoNoNo
Templates: create, edit, toggle, deleteYesYesNoNoNo
Appointments and Service CatalogYesYesView, editView, editView
AnalyticsYesYesYesNoYes
Audit logYesYesNoNoNo
Organisation, channel and pipeline settingsYesYesNoNoNo
View secrets: API keys, Payment Collection, Meta Conversion TrackingYesNoNoNoNo
Invite and manage membersAll roles below OwnerSupervisor, Agent, ViewerNoNoNo
Billing, ownership transfer, deactivate organisationYesNoNoNoNo

The exact permission set behind this table lives in the app's permission map; the table reflects it at the time of writing and the security and roles page tracks changes.

Custom roles

Owners can create a custom role under Settings, then Team, choosing an access level for each of the twelve modules: none, view, edit or full. Levels map to the same underlying permissions as the system roles, so a custom role with Inbox at full and everything else at none behaves like an Agent who can also assign. Custom roles never see secrets and cannot invite members; those stay with Owner and Admin.

Who can manage whom

ActorCan assign or changeCannot touch
OwnerAdmin, Supervisor, Agent, Viewer, custom rolesNothing; ownership moves only through Transfer Ownership
AdminSupervisor, Agent, Viewer, custom rolesOwner and other Admins
Supervisor, Agent, ViewerNobodyTeam settings

How teams change what an Agent sees

Roles decide actions; teams decide scope. An Agent in the Sales team sees unassigned conversations and those assigned to them or to the Sales team, not the Support team's queue. Supervisors, Admins and Owners see every conversation regardless of team. Put a member in more than one team when they cover both queues, and use auto-assignment rules to route new conversations by channel, source or flow choice so the queues fill themselves.

Choosing roles for common setups

SetupSuggested roles
Owner-operated shop with two staffOwner, two Agents
Sales team with a leadOwner, one Supervisor, Agents in a Sales team
Agency managing a client's accountClient as Owner, agency lead as Admin, agency staff as Agents or a custom role
Clinic with reception, nurses and doctorsOwner, reception as Agents, nurses as a custom role (Inbox view, Appointments edit), doctors as Viewers
Finance or auditor accessViewer, or a custom role with Analytics view only

Owner-only actions

  • View or create API keys, and edit Payment Collection and Meta Conversion Tracking settings.
  • Change the plan, cancel the subscription, open the billing portal.
  • Transfer ownership to an Admin or another member (Settings, Danger Zone).
  • Deactivate the organisation, which revokes access for all members immediately.

Settings and options

SettingWhat it doesDefault
Role on inviteSets the member's role at invitationAgent
Team membershipScopes which conversations an Agent seesNo team
Custom rolePer-module access levelsNone until created
Deactivate memberRemoves access and frees the seat; their history staysActive

Troubleshooting

SymptomLikely causeFix
A teammate cannot see Broadcasts or FlowsTheir role is Agent or ViewerChange to Supervisor for analytics, Admin for broadcasts and flows, or a custom role
An Admin cannot open API KeysSecrets are Owner-onlyAsk the Owner, or transfer ownership if the Admin runs the account
Invite fails with a seat errorThe plan's seat limit is reachedDeactivate an unused member or upgrade
An Agent sees conversations from another teamAgents see all unassigned conversationsAssign conversations to teams or use auto-assignment rules

Own records only

Teams where each member handles their own customers - brokers, agents, franchise staff - can build a custom role whose Inbox, Contacts and Leads are limited to Own records. That member then sees conversations, contacts and leads assigned to them, plus anything nobody has claimed yet. Assignment happens automatically: assigning a conversation or a lead assigns its contact to that member if it was unassigned, a member is assigned the contacts they add or import, and a number routed to one person assigns its conversations to them. Owners, admins and supervisors keep full visibility, and a contact's assignee can be changed from its edit dialog (Assigned to), which appears once the workspace has more than one member.

Frequently asked questions

Can a role see only its own contacts and leads?
Yes, with a custom role. For Inbox, Contacts and Leads the role editor has a Can see setting - All records or Own records. Own records means conversations, contacts and leads assigned to them, plus anything not yet assigned to anyone, so an unclaimed record is never invisible to the whole team. Managers on owner, admin or supervisor keep seeing everything. Built-in roles are unchanged.
Which roles are built in?
Five: Owner, Admin, Supervisor, Agent and Viewer. Owners can also create custom roles with a per-module access level.
Who can invite teammates?
Owners can assign Admin, Supervisor, Agent or Viewer. Admins can assign Supervisor, Agent or Viewer. Nobody can create a second Owner; ownership is transferred instead.
Can an Admin see API keys or payment settings?
No. Secrets (API keys, Payment Collection, Meta Conversion Tracking) are visible only to the Owner and platform super admins, even though Admins can edit other settings.
What can an Agent see in the inbox?
Assigned and unassigned conversations. Supervisors and above see every conversation and can assign.
Can a Viewer send messages?
No. Viewers have read-only access to conversations, contacts and analytics.
How do custom roles work?
A custom role sets one of four levels (none, view, edit, full) for each of the twelve modules: Dashboard, Inbox, Contacts, Leads CRM, Broadcasts, Flow Builder, Templates, Analytics, Sales Pipeline, Webhooks, Appointments and Service Catalog.
Is there a seat limit per role?
Seats are counted per plan regardless of role: 1 on Free, 5 on Starter, 15 on Growth, unlimited on Scale.

Run your WhatsApp on VGraple CRM

Free forever plan, official Meta WhatsApp Business API, set up in 15 minutes. No card needed.