A role controls three separate things
Getting one right and forgetting the others is the usual cause of “this user can’t do anything” tickets.1
Permissions — what they can do
Which features and actions they can reach. the role → Edit Permissions.
2
Data scope — how much they can see
Whether they see everything or only their own records.
3
Auto-distribution — whether new chats are dealt to them
Gets new chats puts the role in the rotation for new inbound chats and leads;
No auto-assign keeps the same own-inbox work but only receives what is assigned by
hand. Only available when visibility is “own records only”.
4
Channel access — which conversations reach them
Which channels the role covers, split by 1:1 chats and group rooms.
the role → Channel Access.
Auto-distribution decides who gets chats
A role receives automatically distributed conversations only when its Auto-distribution field is set to Gets new chats. That field can only be turned on for roles whose data scope is own records only — broader-scope roles oversee, they do not queue. Turning it off gives you roles like Account Manager: the same own-inbox work as a sales agent, but they only receive chats a manager hands them.Channel access, and teams
A role with no channel grants receives no conversations, no matter how many permissions it holds. This is also how you build teams without a teams feature:
Distribution runs independently inside each. Membership is decided by permissions and
grants, never by the role’s name, so a duplicated role behaves exactly like the original.
Each grant can cover chats, groups, or both — a role granted only 1:1 chats never receives
a group room.
What you can do with a role
Duplicate, then change the channels is almost always the right way to add a team. It
guarantees the new role has a working permission set, and leaves only one thing to get
right.
Changes made through the help assistant
The help assistant can make some of these changes for you — creating a role, setting its channel access, assigning it to someone. It can only ever do what you have permission for, it always asks before applying anything, and every applied change is written to the audit log attributed to you, with the mechanism recorded. So the log reads “changed via the assistant” rather than hiding how it happened, and a change you approved is your change. Refused and failed attempts are logged too.Troubleshooting
They log in and see almost nothing
They log in and see almost nothing
Permissions. The role grants no access to the features they need.
They see the inbox but never receive a chat
They see the inbox but never receive a chat
Either no channel grants, or the role’s Auto-distribution is No auto-assign (or
its data scope is not “own records only”), so they are outside distribution. See
How assignment works.
They get 1:1 chats but never groups
They get 1:1 chats but never groups
The channel grant covers chats but not groups.
Assigning a chat to them is rejected
Assigning a chat to them is rejected
The error says which gate closed. “No role granting inbox access” is permissions; “no
access to this conversation channel” is channel grants.
They can't open a report
They can't open a report
Analytics is permission-gated, and per-agent KPI detail is admin-only.

