Agent, manager and admin: what each role can do
Three roles with different jobs, drawn along one line: agents own their own work, managers own the operation, admins own what costs money or grants access.
There are three roles and you cannot create a fourth. That constraint is worth understanding rather than working around, because the three are drawn along a line that turns out to be the right one in almost every team.
The line is blast radius. An agent can only affect their own work. A manager can change how work arrives for everybody. An admin can spend money and grant access. Seniority is not the question — a very senior person who never touches routing does not need to be a manager, and a junior ops person who owns the calling hours does.
The most important consequence, and the one that generates the most support questions, is that an agent sees only what is assigned to them. Not "sees everything but filtered by default" — cannot see the rest. Unassigned bot traffic is invisible to them by construction.
Reference
Agent — their own work, and nothing else
An agent sees the chats assigned to them, their own calling list and their own tasks. That is the whole surface.
They get no assignee filter, because with only their own work visible the control would list one name and mean nothing. They do not see the Workflows rail item at all.
The practical consequence: when an agent reports that "the bot is not answering", they are inferring it from silence. They cannot see bot-handled conversations, so they have no evidence either way. Have a manager check with the assignee filter set to None.
An agent can unassign, never reassign
They can take themselves off a conversation. They cannot hand it to a colleague, because that would be pushing work onto somebody who did not agree to it.
Contacts and tasks work the opposite way — anyone can assign either to anyone. The distinction is workload versus records. A conversation is work; a task is a note about work, and restricting it would be noise.
Manager — the whole operation
Managers see every conversation and every teammate, and get the assignee filter, which reads All · None · then every teammate by name.
They own everything that decides how work arrives: routing, calling hours, bots, call flows, campaigns, workflows, and enabling or disabling channels. They can read channel health and act on it.
What a manager deliberately cannot do
Credential fields and the connected-account row on a channel are admin-only. So is billing.
Note that the product shows these controls to managers rather than hiding them. That is intentional: a manager who can see a greyed credential field knows what to ask an admin for, whereas a manager looking at a screen with the field removed concludes the feature does not exist.

Admin — money and access
Admins own what binds the company: billing and plan changes, channel credentials, integrations and API keys, user roles, the contact schema, and export.
Each of those either costs money or grants somebody entry. Connecting a line means a carrier account and a bill. Exporting contacts produces a spreadsheet of personal data with no access control once it leaves the building.
Assign roles by blast radius, not by seniority
Two questions settle almost every case.
"Should a mistake by this person be able to change what happens to everyone else's work?" If yes, they are a manager. "Should a mistake by this person be able to cost money or grant access?" If yes, they are an admin.
Default everybody to agent and promote deliberately. It is much easier to promote someone who asks than to explain why you are demoting them.
Put it to use
Sanity-check your workspace against these three:
- There are at least two admins. One is a single point of failure for billing and credentials.
- Nobody is a manager purely because they are senior. Managers change how work arrives.
- Your agents know that an empty Inbox and a missing Workflows item are both correct.
The parts people get wrong
- An agent can create a booking link that hosts only themselves. Adding other hosts is a manager or admin action, and the page says so rather than showing a control that would be refused.
- Because agents cannot see unassigned traffic, assigning a conversation is also what makes it visible to that person at all. A handover is an assignment.
- Stage and assignee changes are audit-log entries on the contact's activity feed, so a role boundary being crossed leaves a trail either way.
While you are here
Can I create a custom role?
No. The model is three fixed roles applied consistently across every part of the product, and that consistency is the point — one vocabulary for assignment, one for lead stages, one for who may do what. A custom role would mean every screen needing its own answer.
Can a manager see agents' conversations?
Yes. Managers and admins see everything and get the assignee filter reading All · None · then every teammate by name. "None" is the AI bot.
Why can my agent not find the Workflows page?
Agents never see it. Automations change how everyone's work arrives, so building them is a manager and admin action.