Roles and permissions
Every person in a workspace holds exactly one of four roles, and separately has an account status. The role decides what they can reach and who they can talk to; the status decides whether they can get in at all.
The four roles
This is how HushChat describes them on the role picker:
| Role | Description in the app |
|---|---|
| Admin | Full workspace management, sees everyone |
| Member | Regular user, sees everyone |
| Agent | Sees only assigned customers and admins |
| Customer | Sees only assigned agents |
Member is the default. Anyone who joins without you doing anything else arrives as a Member — with one exception, covered below.
What each role can reach
| Admin | Member | Agent | Customer | |
|---|---|---|---|---|
| Send and receive messages | Yes | Yes | Yes | Yes |
| Group conversations | Yes | Yes | Yes | No, once Customer mode is on |
| Web Settings gear | Yes | No | No | No |
| Mobile Admin tab | Yes | No | No | No |
| Invite, Users, Groups, Workspace Settings, Reports, Analytics | Yes | No | No | No |
Every administrator section is administrator-only — there is no partial access, no read-only tier, and no way to grant one section without granting them all. If you need somebody to handle reports or manage groups, they have to be an Admin, with everything else that comes with it.
Non-administrators who follow a direct link to an admin screen are redirected to their chats rather than shown an error.
Changing someone's role
- Open Settings → Users on the web, or the Admin tab → Users on mobile.
- Search for and select the person.
- Under Role, select the role you want. The one they hold now is highlighted and marked Current — you cannot select it again.
- HushChat asks you to confirm. The dialog is titled Change role to {Role} and asks "Are you sure you want to make {name} a {role} of this workspace?"
- Select Make {Role}, or Cancel.
You get Role updated successfully when it works, and Couldn't update role when it does not.
Your own row is not selectable, and the screen tells you: "You cannot change your own role." If you need to demote yourself — or to give yourself the Agent role so you can talk to customers — another administrator has to do it for you. Make sure a second administrator exists before you need one.
Agent is only meaningful with Customer mode on
This is the part that surprises people, so it is worth stating plainly.
With Customer mode off — and it is off by default — the Agent and Customer roles change nothing. An agent sees everyone, can be added to groups, and can message anybody, precisely like a member. Giving somebody the Agent role in a workspace that has never turned Customer mode on has no visible effect whatsoever.
And when Customer mode is on, Agent is not a promotion — it is a restriction. An agent loses things a member has:
- An agent cannot message ordinary members.
- An agent cannot message other agents.
- An agent sees only their assigned customers, plus every administrator.
So the two "restricted" roles are Agent and Customer. Admin and Member are never restricted by Customer mode; they carry on seeing the whole workspace either way.
The rules, once Customer mode is on
| Can this person start a conversation with… | Admin | Member | Agent | Customer |
|---|---|---|---|---|
| Admin | Yes | Yes | Yes | No |
| Member | Yes | Yes | No | No |
| Agent | Yes | No | No | Only if assigned |
| Customer | No | No | Only if assigned | No |
Two consequences catch people out:
- Administrators cannot message customers at all. If you need to reach a customer yourself, give your own account the Agent role and assign yourself to them — and remember you cannot do that last step to yourself, so a second administrator has to.
- Customers are one-to-one only. They cannot be added to groups, and any group they were already in disappears from their conversation list while the role applies.
Turning Customer mode off restores everyone's view immediately. Nothing is deleted by any of this — visibility is worked out fresh each time a screen loads.
For the order to set this up in, see Company setup, end to end. For the switch itself, see Workspace settings overview.
The one time a role is chosen for you
You cannot pick a role when you invite somebody — but while Customer mode is on, everyone you invite arrives holding the Customer role instead of Member. That is the only automatic role assignment in the product. See Invite people.
Account statuses
Separately from the role, each person's membership of the workspace has one of three statuses.
| Status | Meaning | Where you see it |
|---|---|---|
| PENDING | Invited, has not finished registering | Nowhere in the admin UI |
| ACTIVE | A full member of the workspace | The person's screen, as Active |
| SUSPENDED | Blocked from this workspace, reversibly | The person's screen, as Suspended |
Every invitation starts as PENDING and becomes ACTIVE the moment the invitee completes registration.
The Users list deliberately excludes anybody still PENDING, and the status badge on a person's screen only ever reads Active or Suspended — there is no third state shown. So a person you invited an hour ago simply does not exist as far as every administrator screen is concerned, and there is no list of outstanding invitations to check instead. You will only know they arrived when they appear in Users.
Suspension is the one you apply by hand, from Settings → Users → the person → Account Status. A suspended person can still sign in, but choosing your workspace tells them "Your access to this workspace has been suspended. Please contact support." Unsuspend reverses it at any time. Suspending is not the same as removing — see Company setup, end to end for the difference.
A role and a status belong to one workspace, not to a person. The same account can be an administrator in one workspace and a customer in another, and removing or suspending somebody here has no effect on any other workspace they belong to.