Members

Five labels. Here is what each one opens.

Granting access is a security decision, so it should not rest on guessing what a word means. Below is every preset against every menu — and the four powers that stay with you as the owner no matter which preset you pick.

Start here

Nobody needs a preset to answer customers

A new member can answer chats the moment they join. Presets are only about the dashboard — reports, settings, the knowledge base, billing. Their badge reads "Chats only" and that is a complete, working state, not a broken one.

Where they land after signing in follows from that. A member with no dashboard permissions is taken to theAgent Portal — the tool for answering people. A member with any permission at all can also open the dashboard. So "grant access" really means "additionally let this person into the dashboard".

The matrix

Every preset against every menu

RW = can see and change. R = can see only. — = the menu does not appear.

MenuAdminManagerSupport LeadBilling viewerKnowledge editor
ConversationsRWRWRWR
Live ChatRWRWRW
LeadsRWRWRW
Knowledge baseRWRWRRW
DomainsRWRW
Channels & mobile appsRWRW
Dashboards & analyticsRRRR
IntegrationsRWRW
Settings, Conductor & PoliciesRWRW
SecurityRR
Getting startedRWRW
BillingRRR
MembersRWRR
Provider keys

"Billing: R" means the plan, the usage figures and the payment history are visible. Changing the plan or the payment method is not included in any preset — see the next section. Provider keys is a dash the whole way across on purpose: that menu only ever appears for the account owner.

In a sentence each

Which one to reach for

  • Admin — a second pair of hands who runs the account with you. Everything a Manager can do, plus inviting, removing and editing members. Still cannot touch money, AI provider keys, deletion, or anyone's permissions.
  • Manager — runs the account day to day, but the member roster is read-only to them. Right for an operations person you trust with settings but not with staffing.
  • Support Lead — owns the inbox and the people in it. Conversations, live chat and leads in full; the knowledge base and the roster to look at. No settings, no channels, no money.
  • Billing viewer — watches spend without being able to move it. Billing and the dashboards, nothing else. Right for an accountant or a co-founder who only wants the numbers.
  • Knowledge editor — curates what the AI knows, and can read conversations to see where it fell short. Nothing else at all. Right for a freelancer or an intern improving answers.
  • Custom — the same grid, menu by menu, when none of the five fits. Set each menu to none, read, or read and write.
The hard floor

Four powers you cannot give away

Not with a preset, not with the custom grid, not by asking us.

These stay with the account owner, permanently.

1. Changing the plan or payment. Buying, upgrading, downgrading, altering the payment method. Members with Billing access can look; only you can move money.

2. Reading or replacing AI provider keys. Your own OpenAI, Claude or Gemini keys bill your account. Nobody else can read them and nobody else can rotate them. Note that read is withheld as well as write — a key that can be read is a key that can be used elsewhere.

3. Deleting a domain or the account.

4. Granting or revoking anyone's permissions. This is the load-bearing one. An Admin can manage the roster — invite, remove, edit schedules — but if they could also re-scope permissions, every other restriction would be advisory: they could simply grant themselves whatever they lacked. So the two were deliberately split. An Admin who tries is refused.

This is not a UI convention. The restriction is applied when a grant is saved, applied again every time a grant is read, and applied a third time inside the permission check itself. A grant edited directly in the database to carry one of these cannot use it.

A few further screens are owner-only for the same reason, even though they are not part of that grid: approving a member's change of sign-in email, and issuing a key for a mobile app. Anything that changes who someone is, or creates a new way into your account, comes back to you.

Granting it

How to give someone access

1

Open the member

Members & access in your dashboard, then pick the person.

2

Pick a preset, or Custom

The permissions card lists the five presets and Custom. Each shows a one-line description of what it opens. Choosing a preset fills the grid for you; you can still switch to Custom and adjust afterwards.

3

Save, then ask them to reload

The check runs when their dashboard loads, so a reload — or their next sign-in — is when the change takes effect for them.

4

Read the badge back

The badge on the member list is derived from what was actually saved, not from the label you clicked. A preset shows its name; a hand-adjusted grid shows a count such as "6 permissions". That is why it can change from "Manager" to a number after you tick one extra box — the grant is honest about being custom now.

To take access away, set the member back to no permissions. They keep answering chats; they lose the dashboard.

If you are the member

What a support agent can do without any grant

Everything the job needs, and nothing that configures the business:

  • Answer customers in the Agent Portal, and from your phone once you have linked a mobile inbox.
  • Edit your own profile — display name, languages you speak, your own working hours and timezone.
  • See the customers you are handling, and switch between them.

What you will not see is the dashboard: reports, settings, the knowledge base, channels, billing. If you open it and it looks empty, that is a permission state and not a fault — ask the account owner for the access you need, naming the menu rather than a preset. "I need to edit the knowledge base" is an easier request to act on than "I need Manager".

If that did not work

Common surprises

  • "I granted access but they still land in the Agent Portal." Ask them to reload the dashboard, or sign out and in. The permission check runs when the app loads.
  • "I made someone Admin and they still cannot change permissions." Working as intended — that power is not delegable. See the hard floor above.
  • "I ticked Billing but they cannot upgrade the plan." Also intended. Billing access is read-only for everyone except you.
  • "Their badge says a number instead of the preset I picked." The grid was adjusted after the preset was applied, so the grant is genuinely custom now. Re-pick the preset if you want the clean bundle back.
  • "A member reports the dashboard is blank." Check their badge. "Chats only" means no dashboard permissions, which renders as very little. Grant a menu or point them at the Agent Portal.
  • Still unclear? Email support@orcalinq.com with what you want the person to be able to do, in plain words. We will tell you the smallest grant that covers it — smaller is always better than Admin.

Grant the menu, not the title.

Members & access → pick the person → pick the smallest preset that covers the job. Money, keys, deletion and permissions stay with you.