---
title: "Security access groups"
slug: "administration-security-access-groups"
description: "Create and modify custom user access groups (roles) to grant or restrict access to Voiso features."
tags: ["masking", "access", "restricting access", "click-to-call", "click2call", "security", "setup", "administration", "role-based access", "click to call", "role"]
updated: 2026-03-27T10:40:51Z
published: 2026-03-27T10:40:51Z
canonical: "docs.voiso.com/administration-security-access-groups"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://docs.voiso.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Security Access Groups

**Who should read this article**: Administrators

Create and modify custom user access groups (roles) to grant or restrict access to Voiso features.

Important

The Security access groups feature is available for contact centers on the Pro plan or higher.

## Introduction

By default, Voiso provides the following system roles, which can be assigned to a user to grant access to sets of features that are relevant to their job. The roles are:

| Role | Description |
| --- | --- |
| Admin | Access to all features enabled for the contact center |
| Agent | Access to WebRTCSoftphone, outbound calling, click-to-call, contact data, call events, and teams |
| Analyst | Access to CDR and Topics only |
| Hardware phone | Access to login using a Hardware Phone only – no access to WebRTCSoftphone/[Agent Panel](/v1/docs/agent-panel)) |
| Supervisor | Access the same features as the Agent role plus Real-time Dashboards, Call Monitoring and management, Queues, wrap-up codes, Unavailable codes, and Topics |

![Security Access Groups Default Roles](https://cdn.document360.io/44ae307a-3737-4fbf-98e0-9b888deb90dc/Images/Documentation/Security%20Access%20Groups%20Default%20Roles.png)

Voiso customers with the Professional Plus plan may [create](/v1/docs/administration-security-access-groups#creating-a-custom-role) and [assign](/v1/docs/administration-security-access-groups#assigning-a-role) custom access groups to fine-tune the permissions for an access group. For other plans, a limited number of user permissions may be modified when a [user](/v1/docs/users-users) is created or edited.

The following tables provide descriptions of the permissions for each feature area:

- [Administration](/v1/docs/administration-security-access-groups#administration)
- [CDR](/v1/docs/administration-security-access-groups#cdr)
- [Inbound](/v1/docs/administration-security-access-groups#inbound)
- [Messaging](/v1/docs/administration-security-access-groups#messaging)
- [My Numbers](/v1/docs/administration-security-access-groups#my-numbers)
- [Number masking](/v1/docs/administration-security-access-groups#number-masking)
- [Outbound](/v1/docs/administration-security-access-groups#outbound)
- [Real-time dashboard](/v1/docs/administration-security-access-groups#realtime-dashboard)
- [Recordings](/v1/docs/administration-security-access-groups#recordings)
- [Reports](/v1/docs/administration-security-access-groups#reports)
- [Users & Teams](/v1/docs/administration-security-access-groups#users-teams)

#### Administration

| Feature | Description |
| --- | --- |
| Access to Web interface | Log into the Voiso site and use permitted features |
| Enable WebRTC | Use the WebRTCSoftphone/[**Agent Panel**](/v1/docs/agent-panel) (otherwise, the user only has access using a Hardware Phone) |
| Omnichannel Workspace Enabled | Use the [**Omnichannel Workspace**](/v1/docs/omnichannel-workspace) to handle Omnichannel and Voice interactions |
| View Call History | Access to personal call history in **Agent Panel** |
| Allow mobile WebRTC | Use a mobile phone to make calls |
| Enable hardware phone | Use a hardware phone to make calls |
| Allow change password | Allow users to change their own passwords in the [**User Profile**](/v1/docs/user-profile) panel. |
| Edit System settings | Access and use the [**System settings**](/v1/docs/administration-system-settings) page |
| View Integrations | Access to view all integrations on the [**Integrations**](/v1/docs/administration-crm-integration-settings) page. |
| Edit Integrations | Access to add, modify, and configure integrations on the **Integrations** page. |
| Edit Billing | Access and use the **Billing** page |
| View Billing unit | Access the **Billing units** tab on the **Billing** page |
| Edit Billing unit | Access and use the **Billing units** tab on the **Billing** page, including creating, editing, and deleting Billing Units. |
| Allow Feature Access Code | Take control of calls, including initiating monitoring by entering a [DTMF code combination](/v1/docs/administration-system-settings#feature-access-codes) |
| Access to broadcast messages | Access to the [**Broadcast messages**](/v1/docs/messaging-broadcast-messages) page to send messages to teams and view your own messages |
| View all broadcast messages | Access to view all broadcast messages |
| Edit Wrap-up codes | Access to the [**Wrap-up codes**](/v1/docs/administration-wrap-up-codes) page to manage wrap-up codes and wrap-up code groups |
| Edit Unavailable codes | Access to the [**Unavailable codes**](/v1/docs/administration-unavailable-codes) page |
| Edit media files | Access to the [**Media**](/v1/docs/administration-media) page |
| Edit allowed IPs | Access to the [**Allowed hosts/subnets**](/v1/docs/administration-allowed-hosts-subnets) page |
| View allowed IPs | Access to the **Allowed hosts/subnets** page to view allowed hosts/subnets |
| Delete Call Recordings | Access the [**Delete recordings**](/v1/docs/administration-delete-recordings) page |
| Enable 2FA | [Two-factor authentication](/v1/docs/multi-factor-authentication#enabling-2fa-for-your-contact-center) (2FA) is enabled for this user |
| View Topics | Access to view the [**Topics**](/v1/docs/topics) page |
| Edit Topics | Access to the **Topics** page |
| View Keyword Groups | View the [**Keyword groups**](/v1/docs/administration-keyword-groups) page |
| Edit Keyword Groups | Access the **Keyword groups** page to add and delete keywords and keyword groups |
| Edit child Security Access Groups | Access to the Security Access Groups page to view and copy all roles, and to add, copy, edit, and delete custom access groups |
| View API keys | View the list of API keys and key details, including assigned scopes, last used, and audit history. |
| Create API keys | Create new API keys for integrations and assign the required scopes. |
| Edit API keys | Update existing API keys, including renaming keys and changing their assigned scopes. |
| Delete API keys | Delete API keys to revoke access immediately. |

#### CDR

| Feature | Description |
| --- | --- |
| View all CDRs | Access the call detail records ([CDRs](/v1/docs/reporting-cdr)) of all users |
| View team CDRs | Supervisor access the CDRs of assigned team members |
| View call events | Access the **Call Events** table in a call detail record to view all stages of a call |
| View agent’s public IP | Access the public address IP Address of the agent's WebRTC endpoint. |
| View Call transcriptions | When [**Speech analytics**](/v1/docs/speech-analytics) is enabled, view transcripts of calls |
| Download CDR CSV | Allow selected CDRs to be downloaded as a CSV file |
| Allow recordings download | Allow the call recording to be downloaded from a call detail record |

#### Inbound

| Feature | Description |
| --- | --- |
| Create queues | Add and view new [queues](/v1/docs/inbound-queues) |
| Edit all queues | Edit the properties of all queues |
| Edit own queues | Edit the properties of one's own queues only |
| Delete queues | Delete queues |
| Edit scripts | Edit scripts |
| View scripts | View scripts |
| Edit Flows | Edit [inbound interaction flows](/v1/docs/inbound-flows) |
| View Flows | View inbound interaction flows |
| Edit skills | Access and edit the **Skills** section in the **Add queue** page |
| Edit blocked numbers | Access the [**Blocked numbers**](/v1/docs/inbound-call-blocking) page and add or delete numbers or prefixes to the blocklist |
| Edit Allowed inbound voice trunk IPs | Manage the list of trusted IP addresses and subnets that are allowed to send inbound SIP calls to your contact center. |

#### Messaging

| Feature | Description |
| --- | --- |
| View Sender IDs | Access the **Sender IDs** tab in the [**Sender ID groups**](/v1/docs/administration-sender-id-groups) page |
| View Sender ID groups | Access to **Sender ID groups** page |
| View Message Templates | Access the [**Message templates**](/v1/docs/administration-message-templates) page |
| View Canned Messages | Access the **Canned messages** tab on the [**Message templates**](/v1/docs/administration-message-templates) page |
| Edit Sender ID groups | Add, edit, and delete sender ID groups |
| View Digital Channels | Access the [**Digital channels**](/v1/docs/digital-channels) page |
| Edit Digital channels | Add, edit, and delete connections to digital channels such as Telegram, WhatsApp, and Webchat |
| View WhatsApp templates | Access the **WhatsApp** tab on the [**Message templates**](/v1/docs/administration-message-templates) page |
| Edit WhatsApp templates | Add, edit, and delete WhatsApp templates |
| Edit Canned Messages | Add, edit, and delete Canned Messages |
| Display SMS functionality in WebRTC | [Send SMS](/v1/docs/agent-panel) to contacts during and after a call from the **Agent Panel** |

#### My Numbers

| Feature | Description |
| --- | --- |
| Buy numbers | Buy phone numbers from the **Buy numbers** tab in the [**Inbound numbers**](/v1/docs/inbound-inbound-numbers) view |
| Access to Inbound numbers | Access the **Inbound numbers** page |

#### Number masking

| Feature | Description |
| --- | --- |
| Display client numbers instead of Acc ID | Allow the user to view a contact's phone number instead of the contact's account ID or the *Hidden number* placeholder in the [**Redial Counter**](/v1/docs/reporting-redial-counter) and [**Agent List**](/v1/docs/reporting-agent-list) widgets in the [**Real-time dashboard**](/v1/docs/reporting-real-time-dashboard-overview), the [**CDR**](/v1/docs/reporting-cdr), and [**Agent Panel**](/v1/docs/agent-panel-getting-started). |
| Display client number for click-to-call | For [click-to-call](/v1/docs/crm-integration-overview) dialed numbers, allow the user to see a contact's phone number instead of the contact's account ID or the *Hidden number* placeholder in the [**Agent Panel**](/v1/docs/agent-panel-outbound-calls). This setting does not affect interactions with the **click-to-call** type in the [**CDR**](/v1/docs/reporting-cdr)**.** |
| Display client numbers on Dashboard | Allow the user to view a contact's phone number (if permitted by the **Display client numbers instead of Acc ID** permission), account ID (in the case of CRM calls), or the *Hidden number* placeholder in the [**Agent List**](/v1/docs/reporting-agent-list) and [**Redial Counter**](/v1/docs/reporting-redial-counter) widgets in the [**Real-time dashboard**](/v1/docs/reporting-real-time-dashboard). |

#### Outbound

| Feature | Description |
| --- | --- |
| Edit all campaigns | Access the [**Dialer campaigns**](/v1/docs/outbound-dialer-campaigns) page to add, clone, edit, and delete all campaigns |
| Edit own campaigns | Access the **Dialer campaigns** page to add, clone, edit, and delete one's own campaigns |
| Edit CID groups | Add, edit, and delete [Caller ID groups](/v1/docs/outbound-cid-groups) |
| View CID groups | Access the **CID groups** page |
| Access to Caller ID Risk Check | Access the [**Caller ID Risk Check**](/v1/docs/outbound-caller-id-risk-check) page |
| Access to Number validator | Access to the [**Number validator**](/v1/docs/outbound-number-validator) page to check outbound calling numbers |
| Access to Do Not Call Registry | Access to the [**Do Not Call Registry**](/v1/docs/do-not-call-registry) page to upload and manage do-not-call lists. |
| Edit Suppressed numbers | Access to the [**Call Suppression**](/v1/docs/administration-call-supression) page (formerly Hardcaps) |
| Edit Suppressed numbers exceptions | Access to the Call Suppression exceptions feature, with the ability to add, edit, and delete exceptions (formerly Hardcaps) |
| Allow manual outbound calls | Allow manual outbound dialing to external phone numbers |
| Enable Transcriptions with Analytics | Allow user to view call transcripts with [speech analytics](/v1/docs/speech-analytics) in various UIs, including the [CDR](/v1/docs/reporting-cdr). |
| Allow external transfers | Allow user to transfer calls to phone numbers outside the contact center |
| Allow Click-to-call | Allow [Click-to-call](/v1/docs/crm-integration-overview) outbound dialing |
| Enable Answering Machine Detection | Enable [answering machine detection](/v1/docs/use-cases-amd) ({{glossary.AMD}}) for all outbound calls |
| Display HLR Lookup in WebRTC | Allow users to initiate a Home Location Register (HLR) Lookup request, real-time phone number validation, from the call history in the **Agent Panel** |
| Enable Call Notes in WebRTC | Allow users to add [call notes](/v1/docs/call-notes) in the **Agent Panel** |
| Enable Scheduled Callback | Allow user to schedule callbacks from the Agent Panel during an active call or from Call History |

#### Real-time dashboard

| Feature | Description |
| --- | --- |
| View Real-time dashboard | Access the **Real-time dashboard** view |
| Display all data in the ASR by CID by country | In the **ASR by CID by country** Real-time dashboard widget, display all numbers, not just the numbers assigned to teams supervised by the user |
| Allow manager actions | Enable access to manager actions in [**Agent Zoom**](/v1/docs/supervisor-workflows) as a part of the **Agent List** widget capabilities, then use the Allow Monitor, Allow Whisper, Allow Barge-in, Allow Intercept, and Allow Terminate to enable only a subset of **Agent Zoom** capabilities |
| Allow Monitor | Allow Silent Monitoring to enable a Supervisor to listen to a call without distracting the agent |
| Allow Whisper | Allow whisper coaching to enable a supervisor to help agents during a call without the contact hearing the supervisor |
| Allow Barge-in | Allow call barging to enable a supervisor to join a live call and converse with both the contact and the agent |
| Allow Intercept | Allow a supervisor to intercept a call or interaction and redirect it to the supervisor's desktop |
| Allow Terminate | Allow call termination to enable a supervisor to end an agent’s active call from the supervisor dashboard |

#### Recordings

| Feature | Description |
| --- | --- |
| Allow selective recording | Allow the agent to disable and enable call recordings manually in **Agent Panel** during a conversation |

#### Reports

| Feature | Description |
| --- | --- |
| Access to Historical reports | Access to the [**Historical reports**](/v1/docs/reporting-historical-reports) view |
| View ASR per CID report | Allow user to generate and view **ASR per Caller ID** historical report |
| View Sensitive Data Access report | Allow the user to generate and view the **Sensitive Data Access Report** historical report |
| View Billing report | Allow the user to generate and view the **Billing report** historical report |
| View all scheduled reports | Allow the user to view reports scheduled by other users |

#### Users & Teams

| Feature | Description |
| --- | --- |
| Access to Users | Access to the [Users](/v1/docs/users-users) page |
| View user settings | Allow a user to view the list of users and the user profile settings |
| Edit users | Allow a user to edit user profile settings |
| Allow to set Security Access Group | Allow a user to change the [Security Access Group](/v1/docs/administration-security-access-groups#assigning-a-role) for users and set the Security Access Group for new user |
| Allow editing of support chat users | Allow a user to grant the [premium support chat](/v1/docs/premium-chat-support) feature to up to three users |
| Delete users | Allow a user to delete user profiles |
| Create users | Allow a user to create new user profiles |
| Bulk users upload | Allow a user to create users by importing a CSV file |
| View teams | Access to the [**Teams**](/v1/docs/users-teams) view |
| Edit teams | Allow a user to create, edit, and delete teams |
| Access to data of all users | Access to user data in all system components |
| Access to data of team users | Access to team data in all system components |

## Creating a custom access group

If the default Security Access Groups do not meet your organization's needs, you can create custom root access groups. There are two approaches to creating new access groups: creating a new access group "from scratch" or clone and then modifying an existing access group. The first approach means that you have to consider every single setting. In contrast, the second approach means you only have to disable one or more settings to differentiate your custom access group from the existing one.

### Creating a custom access group from scratch

To create a new custom access group beginning with all permissions enabled, follow these steps:

1. From the Voiso navigation bar, select **Administration > Security access groups**.
2. In the **Security Access Groups** page, click **Add new access group**.
3. All permissions are initially granted except for **Enable hardware phone** in the **Create Security Access Group** page.
4. Add a name in the **Group name** field.
5. Review each permission and de-select the ones you do not want to grant to the access group.
6. Click **Save**.
7. [Assign the new access group](/v1/docs/administration-security-access-groups#assigning-a-role) to one or more [users](/v1/docs/users-users).

![Security Access Groups Overview](https://cdn.document360.io/44ae307a-3737-4fbf-98e0-9b888deb90dc/Images/Documentation/Security%20Access%20Groups%20Overview.gif)

### Creating a custom access group from a clone

When you clone an access group, you cannot add new permissions, and you can only disable permissions to make the new access group more restrictive than the cloned access group. To create a new custom access group based on an existing access group, follow these steps:

1. From the Voiso navigation bar, select **Administration > Security Access Groups**.
2. In the **Security Access Groups** page, hover your mouse pointer over the group to be cloned, then click **Clone**.
3. Add a name in the **Group name** field.
4. In the **Clone Security Access Group: <access group>** page, de-select the permissions you want to disable for the new access group.
5. Click **Save**.
6. The new access group appears on the **Security Access Groups** page as a sub-access group of the access group you cloned.

![Security Access Groups Clone Role](https://cdn.document360.io/44ae307a-3737-4fbf-98e0-9b888deb90dc/Images/Documentation/Security%20Access%20Groups%20Clone%20Role.gif)

### Exporting custom groups as a CSV

To enable you to copy your custom Security Access Groups from one contact center to another, follow these steps to export your custom Security Access Groups:

1. From the Voiso navigation bar, select **Administration > Security Access Groups**.
2. In the **Security Access Groups** page, click **Export CSV**.
3. A CSV file named `security-access-groups-export.csv` is downloaded to your computer. It contains a list of the configuration setting names on the first row and your custom Security Access Groups on subsequent rows in the following format, where y = enabled and n = disabled:

```plaintext
child_group_name,parent_group_name,n,n,n,n,n,n,n,n,n,n,n,n,n,n,n,n,n,n,n,n,n,n,n,n,n,n,n,n,n,n,n,n,n,n,n,n,n,n,n,n,n,n,y,y,n,y,n,n,n,n,y,n,n,n,n,n,n,n,n,n,n,y,n,n,y,n,n,n,n,n,n,n,n,n,n,n,n,n,n
```

### Importing custom groups from a CSV

To enable you to copy your custom Security Access Groups from one contact center to another, follow these steps to import your custom Security Access Groups:

1. From the Voiso navigation bar, select **Administration > Security Access Groups**.
2. In the **Security Access Groups** page, click **Import CSV**.
3. Navigate to the location where you stored the Security Access Groups CSV [you previously exported](/v1/docs/administration-security-access-groups#exporting-custom-groups-as-a-csv), then click **Upload**.
4. Click **Process**.
5. The message **Done!** displays when your imported Security Access Groups are ready to use.

![Security Access Groups Import CSV](https://cdn.document360.io/44ae307a-3737-4fbf-98e0-9b888deb90dc/Images/Documentation/Security%20Access%20Groups%20Import%20CSV.gif)

## Assigning an access group

When the Security Access Groups feature is enabled, all [users](/v1/docs/users-users) must have a **Security Access Group** assigned (this is the same as the **Role** for Professional and Start-up plans). By default, new users are created with the **Agent** security access group. To assign an access group to a user, follow these steps:

1. From the Voiso navigation bar, select **Users > Users**.
2. In the **New User** or **Edit User** page, select a Security Access Group from the **Security access group** menu.
3. Click **Save**.

![Security Access Groups Assign SAG](https://cdn.document360.io/44ae307a-3737-4fbf-98e0-9b888deb90dc/Images/Documentation/Security%20Access%20Groups%20Assign%20SAG.png)

## Deleting a Security Access Group

You can delete custom Security Access Groups. To delete a custom access group, follow these steps:

1. From the Voiso navigation bar, select **Administration > Security Access Groups**.
2. In the **Security access groups** page, hover your mouse pointer over the group to be deleted, then click **Delete**.

Web Real-Time Communication. A technology that enables the use of a web browser to make a phone call. The Voiso Agent Panel is a WebRTC-based softphone.

A software application that enables users to make telephone calls over the internet using a computer, tablet, or mobile device and a high-speed internet connection.

Events are significant changes of state for a call. For example, when a call is dialed, a dialing event is generated for the call. Voiso logs the time of call events.

Agents working under a common supervisor are considered to be a part of a team. Teams enable you to group users together for common business purposes. You can create many different teams for different business purposes. A user may be assigned to more than one team and a supervisor may supervise more than one team. You can assign agents to Dialer campaigns and Caller ID groups either individually or as part of a team.

See Call Detail Record.

A physical telephone connected to a contact center's phone network. In contrast to a softphone like the Voiso Agent Panel, hardware phones have limited capabilities. They are best suited to situations where you want to limit agent access to your system.

In a contact center, the person responsible for leading, monitoring, and training a team of agents.

A user who handles inbound and/or outbound interactions with contact. Sometimes referred to as a Customer Service Representative (CSR). The front-line employee who interacts directly with contacts and assists with tasks such as placing orders, resolving billing issues, and answering policy questions.

A display on a computer screen that enables easy viewing of real-time data, communication, KPI reporting, or technical information.

Agent monitoring is a quality management and/or performance activity in which a supervisor listens to an active call without the agent or contact being aware of the supervisor's presence.

A technology that places inbound voice calls and omnichannel interactions into a virtual waiting line in which contacts waits to be connected with an agent. Queues direct calls to the best available agent to reduce waiting times. Interactions with different priorities can be assigned to different queues. Queues can play music and other messages to callers waiting to connect to agents. Voiso queues also offer contacts a callback option if the wait time on the queue is long.

An agent status. The agent is logged in, but is not available to handle interactions. Unavailable with a reason, such as lunch break or team meeting. Also, an agent metric: the duration an agent was in the **Unavailable** (with reason) status after login.

Contacts can move seamlessly between one communication channel and another, while the contact center tracks all the interactions as a single conversation. A conversation might begin as a webchat, progress to a phone call, and conclude with a offer being made by WhatsApp. This is an advance over multichannel where a contact center offers multiple, but unrelated communication channels, such as voice, webchat, WhatsApp, and so on.

Comma-Separated Values. A data file format where the content is structured in tabular form. Fields (data values) are separated by commas. Rows (records) are separated by line feeds. Voiso supports UTF-8 format for CSV files. CSV files allow interchange of data between spreadsheet applications, text files, and database. It is a common format for importing and exporting data. Each row represents a record. Each value represents an attribute.

A telephone prefix is the first set of digits after the country and area codes of a telephone number: country code + area code + prefix + subscriber number. The prefix is sometimes associated with a region (exchange) within the area represented by the area code.

The identification phone number used to send an SMS. The number that is displayed to the message recipient. SIDs might become flagged by phone network providers if they are reported as SPAM or fraudulent.

Short Message/Messaging Service. A text messaging service component of telephone, Internet, and mobile devices. It uses standardized communication protocols that lets mobile devices exchange short text messages. Voiso enables agents to send SMS to contacts.

Caller ID. The identification phone number used for an outbound call. The number that is displayed to the call recipient. CIDs might become flagged by phone network providers if they are reported as SPAM or fraudulent.

CID. The identification phone number used for an outbound call. The number that is displayed to the call recipient. CIDs might become flagged by phone network providers if they are reported as SPAM or fraudulent.

A phone number that is outside of the contact center dialing system. Within an organization, an external phone number might refer to a cellphone, softphone, or hardware phone that cannot be reached by dialing a contact center extension number.

Home Location Register. A database containing information about authorized subscribers using a global system for mobile communication (GSM) core network. The home location register stores information ranging from phone numbers to current location of the subscriber.

ASR (Answer Seizer Ratio) is a telephony metric that measures the percentage of successfully connected outbound calls. It is calculated as:

**ASR = (Answered calls ÷ Total call attempts) × 100**

A higher ASR generally indicates better call quality, routing, or list effectiveness, since more dialed calls reach a person or endpoint.

Agent monitoring is a quality management and/or performance activity in which a supervisor listens to an active call without the agent or contact being aware of the supervisor's presence.

Supervisor can join a call to help agents without the contact hearing the supervisor.

Supervisors can join a live call and converse with both the contact and the agent.

When a supervisor takes a call that was routed to an agent.

To end a voice call. Hang up a voice call either manually or automatically.

## Related

- [Users](/users-users.md)
- [Teams](/users-teams.md)
- [Supervisor Guide](/supervisor-workflows.md)
- [Historical reports overview](/reporting-historical-reports-overview.md)
- [Real-time dashboard overview](/reporting-real-time-dashboard-overview.md)
- [Dialer campaigns overview](/outbound-dialer-campaigns-overview.md)
