Role-Based Access Control

Control who can access and modify what in your Zowie workspace with Role-Based Access Control (RBAC). This guide explains how to create roles, assign permissions, and manage team access across your organization.


Table of Contents

  1. Understanding RBAC
  2. Role Types
  3. Managing Roles
  4. Assigning Roles to Users
  5. Predefined Roles
  6. Workspace Permissions Reference
  7. AI Agent (Automate) Permissions Reference

Understanding RBAC

Role-Based Access Control (RBAC) lets you define exactly what each team member can see and do within Zowie. Instead of giving everyone full access, you create roles with specific permissions, then assign these roles to team members.

Key Concepts

TermDescription
PermissionA single capability, like "View Knowledge Base" or "Create Processes"
RoleA collection of permissions bundled together (e.g., "Knowledge Manager")
AssignmentConnecting a role to a specific user

Benefits

  • Security: Limit access to sensitive features like billing or API headers
  • Compliance: Control who can publish changes to production
  • Organization: Different teams get access only to what they need
  • Accountability: Track who has access to what through audit logs coming soon


Role Types

Zowie has two distinct role types, each controlling access to different parts of the platform:

1. Workspace Roles

Workspace roles control access to organization-wide settings that affect your entire Zowie account.

Scope: One role per user across the entire workspace

Controls access to:

  • Team management (inviting members, managing roles)
  • Availability settings (working hours, out-of-office)
  • Customer segmentation (properties, segments)
  • Integrations (Zendesk, Shopify, Salesforce, etc.)
  • AI Agent management (creating/deleting AI Agents)
  • Billing information
  • Workspace settings

2. AI Agent Roles (Automate)

AI Agent roles control access to the configuration of individual AI Agents. This allows fine-grained control over who can modify each chatbot.

Scope: One role per user per AI Agent - the same user can have different roles for different AI Agents

Controls access to:

  • Start configuration
  • Regional settings and glossary
  • Processes, data types, and variables
  • Channels (Zowie Chat, Messenger, WhatsApp, etc.)
  • Testing scenarios
  • Personality (Persona and Guidances)
  • Knowledge base
  • Routing rules
  • Handovers and surveys
  • Versioning and staging
  • Dashboards and supervisor tools
  • Plugins

Comparison Table

AspectWorkspace RoleAI Agent Role
ScopeEntire workspacePer AI Agent
Assignments per userOneOne per AI Agent
Example use"Only admins can manage billing""Marketing team can only edit the Marketing AI Agent"

Managing Roles

Accessing Role Management

  1. Navigate to Team in the workspace sidebar
  2. Click on the Roles tab
  3. Here you can view, create, edit, and delete roles

Creating a New Role

  1. Click Create New Role in the top-right corner
  2. Fill in the role details:
    • Name: A descriptive name (e.g., "Content Editor", "Bot Administrator")
    • Description: Explain what this role is for
    • Type: Choose either Workspace or AI Agent
  3. Select the permissions for this role (see Permissions Reference)
  4. Click Save

Editing a Role

  1. Find the role in the Roles list
  2. Click the Edit icon (pencil)
  3. Modify the name, description, or permissions
  4. Click Save

Note: You cannot change the role type (Workspace vs AI Agent) after creation.


Deleting a Role

  1. Find the role in the Roles list
  2. Click the Delete icon (trash)
  3. Confirm the deletion

Important: You can only delete roles that are not currently assigned to any users. If the delete button is disabled, the role is still in use.



Assigning Roles to Users

Assigning a Workspace Role

Each user can have one Workspace role. To assign:

  1. Navigate to Team > Members
  2. Click on a team member to edit their profile
  3. In the Workspace Role section, select a role from the dropdown
  4. Click Save

Assigning AI Agent Roles

Users can have different roles for each AI Agent. To assign:

  1. Navigate to Team > Members
  2. Click on a team member to edit their profile
  3. In the AI Agent Access section:
    • Ensure the Automate product toggle is enabled
    • For each AI Agent listed, select the appropriate role
    • Users can have "No role" (no access) or any AI Agent role
  4. Click Save

Assigning Roles During AI Agent Creation

When creating a new AI Agent:

  1. After configuring the basic settings, you'll see a Who has access? section
  2. All users with Automate access are listed
  3. Assign roles to determine who can access the new AI Agent

Predefined Roles

Zowie provides predefined Super Admin roles for both role types. These roles grant full access and cannot be modified or deleted.

Workspace - Super Admin

Role NameDescriptionPermissions
Workspace - Full AdminFull access to all workspace featuresAll Workspace permissions

This role grants complete control over the whole Workspace.

Automate - Super Admin

Role NameDescriptionPermissions
Automate - Fill AdminFull control over the AI AgentAll AI Agent permissions

This role grants complete control over the whole AI Agent.


Workspace Permissions Reference

Workspace permissions are organized into categories. Here is a complete reference of all available permissions:

Team Management

Control who can manage your organization's users and roles.

PermissionDescription
View MembersView the list of team members and their details
Invite MemberInvite new users to join the workspace
Update MemberModify existing member details and role assignments
Delete MemberRemove users from the workspace
View RolesView available roles and their permissions
Create RoleCreate new custom roles
Update RoleModify existing role names, descriptions, and permissions
Delete RoleRemove unused roles from the system

Availability

Control access to working hours and out-of-office settings that determine when your AI Agents are active.

PermissionDescription
View Working HoursView configured working hours schedules
Create Working HoursCreate new working hours schedules
Update Working HoursModify existing working hours
Delete Working HoursRemove working hours schedules
View Out of OfficeView out-of-office periods and holidays
Create Out of OfficeCreate new out-of-office periods
Update Out of OfficeModify existing out-of-office settings
Delete Out of OfficeRemove out-of-office periods

Customer Segmentation

Control access to customer properties and segments used for personalizing AI Agent behavior.

PermissionDescription
View PropertiesView customer property definitions
Create PropertiesDefine new customer properties
Update PropertiesModify existing property definitions
Delete PropertiesRemove property definitions
View SegmentsView customer segment definitions
Create SegmentsCreate new customer segments
Update SegmentsModify existing segment rules
Delete SegmentsRemove segment definitions

Integrations

Control who can connect and manage third-party integrations.

PermissionDescription
View IntegrationsView connected integrations and their status
Create IntegrationConnect new third-party integrations
Update IntegrationModify integration configuration
Delete IntegrationDisconnect integrations

AI Agent Management

Control who can create, modify, and delete AI Agents at the workspace level.

PermissionDescription
Create AI AgentCreate new AI Agents in the workspace
Update AI AgentModify AI Agent basic settings (name, etc.)
Delete AI AgentArchive AI Agents

Billing

Control access to billing and subscription information.

PermissionDescription
View BillingView billing section

Workspace Settings

Control access to global workspace configuration.

PermissionDescription
View SettingsView workspace configuration and settings
Modify SettingsChange workspace settings


AI Agent (Automate) Permissions Reference

AI Agent permissions control what users can do within each specific AI Agent. These are assigned per AI Agent, allowing granular control over who can modify which bot.

Start Configuration

Control access to the AI Agent's initial greeting and configuration.

PermissionDescription
View StartView the start/greeting configuration
Update StartModify greeting messages and initial agent behavio

Regional Settings & Localization

Control access to language settings, regions, and glossary.

PermissionDescription
View LocalizationView regional settings, language configurations, and glossary
Create LocalizationAdd new regions or glossary entries
Update LocalizationModify regional settings and glossary terms
Delete LocalizationRemove regions or glossary entries

Processes

Control access to Decision Engine Processes

PermissionDescription
View ProcessesView process definitions and workflow diagrams
Create ProcessBuild new automation processes
Update ProcessModify existing process logic and flows
Delete ProcessRemove processes from the AI Agent

[SCREENSHOT: Process permissions section in the AI Agent Role Form]

Data Types

Control access to custom data type definitions used in Processes.

PermissionDescription
View Data TypesView data type definitions and schemas
Create Data TypeDefine new custom data types
Update Data TypeModify existing data type schemas
Delete Data TypeRemove data type definitions

Variables

Control access to variables used across Processes.

PermissionDescription
View VariablesView variable definitions and values
Create VariableCreate new variables
Update VariableModify variable values and configurations

Channels

Control access to communication channel configurations.

PermissionDescription
Zowie ChatManage Zowie's native chat widget (Widget, Embedded, Standalone, Mobile SDK)
Other ChannelsManage third-party channels (Messenger, Instagram, WhatsApp, Zendesk, Intercom, Viber, etc.)

Testing

Control access to Testing page.

PermissionDescription
View TestingView test cases and results
Create TestingCreate new test scenarios
Update TestingModify existing test cases
Delete TestingRemove test scenarios

Versioning & Version Values

Control access to version-specific variables that can differ between staging and production.

PermissionDescription
View Version ValuesView version-specific variable configurations
Create Version ValueCreate new version-specific values
Update Version ValueModify version-specific configurations
Delete Version ValueRemove version-specific values

Staging & Deployment

Control access to the staging environment and production deployment.

PermissionDescription
View VersionsView available versions in staging
View ChangelogView deployment history and changelogs
Create VersionCreate new versions in staging
Delete VersionRemove versions from staging
Publish VersionDeploy versions to production

Personality - Persona

Control access to the AI Agent's personality and tone configuration.

PermissionDescription
View PersonaView the AI Agent's personality settings
Update PersonaModify personality, tone, and voice settings

Personality - Guidances

Control access to specific behavioral guidelines for the AI Agent.

PermissionDescription
View GuidancesView guidance rules and instructions
Create GuidanceAdd new behavioral guidelines
Update GuidanceModify existing guidance rules
Delete GuidanceRemove guidance rules

Knowledge

Control access to the AI Agent's knowledge base.

PermissionDescription
View KnowledgeView knowledge base content and sources
Create KnowledgeAdd new knowledge sources or entries
Update KnowledgeModify existing knowledge content
Delete KnowledgeRemove knowledge sources or entries

Routing

Control access to intent routing

PermissionDescription
View RoutingView routing rules and intent configurations
Create RoutingCreate new routing rules
Update RoutingModify existing routing logic
Delete RoutingRemove routing rules

Transfers & Handovers

Control access to handover rules that transfer conversations to human agents.

PermissionDescription
View TransfersView handover configurations and rules
Create TransferCreate new handover rules
Update TransferModify existing handover configurations
Delete TransferRemove handover rules

Surveys

Control access to pre-chat and post-chat survey configurations.

PermissionDescription
View SurveysView survey configurations
Create SurveyCreate new surveys
Update SurveyModify existing survey questions and logic
Delete SurveyRemove surveys

Dashboards

Control access to analytics dashboards.

PermissionDescription
Supervisor DashboardAccess the AI Supervisor dashboard with real-time insights
Home DashboardAccess the main analytics dashboard

Supervisor

Control access to conversation monitoring and debugging tools.

PermissionDescription
View TranscriptsView conversation transcripts and history
View Audit LogsAccess detailed audit logs for debugging
View API HeadersView API request/response headers (sensitive data)

Plugins

Control access to plugin management and configuration.

PermissionDescription
Manage PluginsEnable, disable, and configure plugins (Privacy Compliance, A/B Testing, Proactive Chats, etc.)