Platform

Roles & permissions that actually fit how your team works

Owner, admin, member — plus custom roles. Granular controls per WhatsApp number, bot, campaign, contact list. Audit logs on every action. Ready for enterprise from day one.

3

Built-in roles

Owner / Admin / Member

Custom

Roles

Define your own

Per-resource

Access

Number, bot, list, campaign

Audit log

Every action

Full traceability

Granular access controls without complexity

Built-in roles

Owner: full control, billing, workspace settings. Admin: configure bots, campaigns, integrations. Member: send messages, view assigned conversations. Right defaults for 80% of teams.

Custom roles

Define your own roles by combining permissions. 'Campaign Manager' (campaigns + contacts), 'Support Lead' (inbox + bot config), 'Read-only Auditor' (view everything, edit nothing).

Per-resource access

Restrict roles to specific WhatsApp numbers, bots, contact lists, or campaigns. Sales team sees only Sales line; Support sees only Support line.

Workspace invitations

Invite users by email with a specific role pre-assigned. They get a magic link to join. Invitations expire after 7 days; auditable revocation anytime.

Audit log

Every privileged action logged: who created the bot, who deleted that template, who exported the contact list, who changed a role. Export to SIEM if needed.

API key scoping

API keys inherit permissions of the role they're issued under. Generate scoped keys for specific integrations (e.g. 'read-only contacts API').

Inviting a team and assigning roles

  1. 1

    Invite by email + role

    From Workspace Settings → Members, enter teammate emails and pick a role for each. They receive a Keycloak-backed invite link to join.

  2. 2

    Set per-resource scopes (optional)

    For roles that need scoped access, restrict to specific resources. 'Anjali can manage the Hindi number's bot but not the English one.'

  3. 3

    Teammates sign up + land in workspace

    First-time users go through Keycloak OAuth. Returning users authenticate once and access the workspace immediately.

  4. 4

    Monitor activity in audit log

    Workspace Settings → Audit Log shows every action with timestamp, actor, resource, and outcome. Filter by date, user, action type.

  5. 5

    Adjust roles as team evolves

    Promote a member to admin, restrict a role's scope, revoke access — all from the same page. Changes take effect within seconds.

RBAC — Edesy vs typical platform

FeatureEdesyTypical competitor
Built-in roles31–2
Custom rolesEnterprise tier only
Per-resource scoping
API key role inheritance
Audit log on all actionsLimited
Email invitations with magic link
Scope by WhatsApp number
Scope by bot / contact list

Roles in real organizations

Agency with 15 client workspaces

Each client gets their own workspace. Agency team has admin role across all; client owners have admin in their own workspace only. Clean isolation.

Zero accidental cross-client data exposure

Mid-size company — multi-team

Marketing team handles campaigns. Support team handles inbox. Ops team handles integrations. Custom roles enforce least-privilege.

Onboarding new team members takes 5 min, not 5 hours

Enterprise — auditor role

Created a read-only Auditor role for compliance team. They can see every conversation and configuration but can't modify anything.

Passed SOC 2 audit with this configuration

BPO running for external client

Client's brand needs WhatsApp service but doesn't want to give full access to a BPO. BPO agents get scoped Member role on one number only.

Client trust + audit trail meets contractual requirements

Multi-country with regional ops

India team manages India number; LatAm team manages Mexico/Brazil numbers. Region-scoped admin roles per local team.

Local teams move fast without stepping on each other

Startup with consultant

Brought on a part-time WhatsApp consultant. Gave them admin scoped to one bot only. Revoked access after project. Audit log proves what they did.

Clean handoff, no lingering risk

Why RBAC quality determines whether you can sell to enterprise

Most WhatsApp platforms ship a single 'team member' role and call it done. That works fine until you try to scale past 5 users — then suddenly you need 'this person can run campaigns but shouldn't see contact lists', 'that auditor needs read access to everything but write access to nothing', 'the BPO agents should only see the support inbox, not the marketing one'. Without proper RBAC, your only options are 'give everyone admin' (terrifying) or 'don't give them access at all' (operationally painful).

Edesy's RBAC is built on three layers. Built-in roles cover the common cases (Owner, Admin, Member) — most workspaces never need anything else. Custom roles let you define your own permission combinations for unusual structures (auditor, regional manager, campaign-only operator). Per-resource scoping is the third layer: you can restrict any role to specific WhatsApp numbers, bots, or contact lists. So 'Admin on the Hindi number, no access to English' is one toggle, not a system you have to build yourself.

The audit log is the unsexy feature that closes enterprise deals. Every privileged action — creating, modifying, deleting bots / templates / contacts / campaigns; viewing exported data; rotating API keys — gets logged with actor, timestamp, IP, and outcome. The log is queryable, exportable, and tamper-evident. When a CISO asks 'who deleted that contact list last Tuesday?', you have the answer in 10 seconds. When auditors ask for proof of separation of duties, you generate the report on the spot.

API key role inheritance is a quieter superpower. When you create an API key, it inherits the permissions of the user who created it. Generate a read-only key for your data warehouse ETL — that key can never accidentally modify data, even if it's compromised. Generate a campaign-only key for your marketing automation — it can't access the inbox or modify bots. This level of API key scoping is rare in WhatsApp platforms and a clear differentiator when developer teams evaluate options.

Frequently asked questions

Set up your team with the right access

Free workspace, all roles included. Most teams configure roles + invite their full team within 30 minutes.