Skip to main content

Roles and permissions

Every person in a workspace holds exactly one of four roles, and separately has an account status. The role decides what they can reach and who they can talk to; the status decides whether they can get in at all.

The four roles

This is how HushChat describes them on the role picker:

RoleDescription in the app
AdminFull workspace management, sees everyone
MemberRegular user, sees everyone
AgentSees only assigned customers and admins
CustomerSees only assigned agents

Member is the default. Anyone who joins without you doing anything else arrives as a Member — with one exception, covered below.

What each role can reach

AdminMemberAgentCustomer
Send and receive messagesYesYesYesYes
Group conversationsYesYesYesNo, once Customer mode is on
Web Settings gearYesNoNoNo
Mobile Admin tabYesNoNoNo
Invite, Users, Groups, Workspace Settings, Reports, AnalyticsYesNoNoNo

Every administrator section is administrator-only — there is no partial access, no read-only tier, and no way to grant one section without granting them all. If you need somebody to handle reports or manage groups, they have to be an Admin, with everything else that comes with it.

Non-administrators who follow a direct link to an admin screen are redirected to their chats rather than shown an error.

Changing someone's role

  1. Open SettingsUsers on the web, or the Admin tab → Users on mobile.
  2. Search for and select the person.
  3. Under Role, select the role you want. The one they hold now is highlighted and marked Current — you cannot select it again.
  4. HushChat asks you to confirm. The dialog is titled Change role to {Role} and asks "Are you sure you want to make {name} a {role} of this workspace?"
  5. Select Make {Role}, or Cancel.

You get Role updated successfully when it works, and Couldn't update role when it does not.

You cannot change your own role

Your own row is not selectable, and the screen tells you: "You cannot change your own role." If you need to demote yourself — or to give yourself the Agent role so you can talk to customers — another administrator has to do it for you. Make sure a second administrator exists before you need one.

Agent is only meaningful with Customer mode on

This is the part that surprises people, so it is worth stating plainly.

Outside Customer mode, an Agent is exactly a Member

With Customer mode off — and it is off by default — the Agent and Customer roles change nothing. An agent sees everyone, can be added to groups, and can message anybody, precisely like a member. Giving somebody the Agent role in a workspace that has never turned Customer mode on has no visible effect whatsoever.

And when Customer mode is on, Agent is not a promotion — it is a restriction. An agent loses things a member has:

  • An agent cannot message ordinary members.
  • An agent cannot message other agents.
  • An agent sees only their assigned customers, plus every administrator.

So the two "restricted" roles are Agent and Customer. Admin and Member are never restricted by Customer mode; they carry on seeing the whole workspace either way.

The rules, once Customer mode is on

Can this person start a conversation with…AdminMemberAgentCustomer
AdminYesYesYesNo
MemberYesYesNoNo
AgentYesNoNoOnly if assigned
CustomerNoNoOnly if assignedNo

Two consequences catch people out:

  • Administrators cannot message customers at all. If you need to reach a customer yourself, give your own account the Agent role and assign yourself to them — and remember you cannot do that last step to yourself, so a second administrator has to.
  • Customers are one-to-one only. They cannot be added to groups, and any group they were already in disappears from their conversation list while the role applies.

Turning Customer mode off restores everyone's view immediately. Nothing is deleted by any of this — visibility is worked out fresh each time a screen loads.

For the order to set this up in, see Company setup, end to end. For the switch itself, see Workspace settings overview.

The one time a role is chosen for you

You cannot pick a role when you invite somebody — but while Customer mode is on, everyone you invite arrives holding the Customer role instead of Member. That is the only automatic role assignment in the product. See Invite people.

Account statuses

Separately from the role, each person's membership of the workspace has one of three statuses.

StatusMeaningWhere you see it
PENDINGInvited, has not finished registeringNowhere in the admin UI
ACTIVEA full member of the workspaceThe person's screen, as Active
SUSPENDEDBlocked from this workspace, reversiblyThe person's screen, as Suspended

Every invitation starts as PENDING and becomes ACTIVE the moment the invitee completes registration.

Pending members are invisible to you

The Users list deliberately excludes anybody still PENDING, and the status badge on a person's screen only ever reads Active or Suspended — there is no third state shown. So a person you invited an hour ago simply does not exist as far as every administrator screen is concerned, and there is no list of outstanding invitations to check instead. You will only know they arrived when they appear in Users.

Suspension is the one you apply by hand, from SettingsUsers → the person → Account Status. A suspended person can still sign in, but choosing your workspace tells them "Your access to this workspace has been suspended. Please contact support." Unsuspend reverses it at any time. Suspending is not the same as removing — see Company setup, end to end for the difference.

Roles are per workspace

A role and a status belong to one workspace, not to a person. The same account can be an administrator in one workspace and a customer in another, and removing or suspending somebody here has no effect on any other workspace they belong to.