Our standard Intercom configuration includes nine distinct roles, each designed to provide the appropriate level of access and permissions for different team members.
Below, we explain each role, the foundational permissions that all roles receive, and the specific permissions unique to each role.
Standard roles
Role | Purpose | Key features |
Administrator | Full system access for workspace administrators | Complete access to settings, users, and data. Reserved for members of the Central Digital CX team |
Conversations | Front-line customer support agents | Access to Conversations and basic reporting |
Conversations manager | Team leads managing conversation workflows | Enhanced conversation management capabilities |
Outbound lite | Limited outbound messaging capabilities | Basic outbound messaging and proactive support tools |
Outbound full | Complete outbound messaging functionality | Full suite of outbound messaging and workflow tools |
Content creator lite | Basic content creation and management | Limited content creation with draft permissions |
Content creator full | Complete article management capabilities | Full content creation, editing, and publishing rights |
Reporting view-only | Access to reporting data without modification rights | Read-only access to reports and analytics |
Technical implementation | Technical setup and integration management | Developer tools and app configuration access |
Foundational permissions
The following permissions are granted to all roles as part of our standard configuration:
Basic access rights
Can change status: All team members can update their availability status.
Can access people, companies, and account lists: Universal access to customer contact information.
Can access lead and user profiles: View customer profile data.
Can export lead, user, company data: Download contact information.
Reporting access
Can access reports: View reporting dashboard.
Can create, edit and internally share reports: Collaborate on reporting insights.
Can schedule and download PDFs of reports: Export report data.
Can export CSV: Download data in spreadsheet format.
Can access chart drill-in: Detailed data exploration.
Can manage Workspace folders: Organise reports and resources.
Dashboard access
Can access real-time dashboard: Monitor live activity and metrics.
Role-specific permissions
Administrator
Administrators have complete system control, including:
Settings management: Full access to general, security, billing, and integration settings.
User management: Can manage teammates, seats, permissions, and teams.
Data control: Complete workspace data access and import capabilities.
System configuration: Automation, assignment rules, and advanced features.
Fin AI Copilot usage: Access to AI assistance tools.
📌 Note: This role should only be provided to the Central Ops team.
Conversations & Conversations Manager
Conversations role
Inbox seat license: Full conversation access.
Copilot: Included usage only.
Basic conversation tools: Can use personal macros.
Limited management: No advanced conversation management features.
This role is used for Support and Onboarding agents.
Conversations Manager role
Includes all Conversations permissions plus:
Advanced management: Can reassign conversations, edit ownership, and delete replies.
Team tools: Manage shared macros, views, rules, teams and teammate presence.
Call features: Can listen in on calls and remove SLA restrictions.
This role is used for Support Team Leaders.
Outbound roles
Depending on the access required, either of these can be assigned to CSMs, Digital CSMs and Marketing.
Outbound Lite
Basic messaging: Can bulk message contacts and publish news.
Proactive tools: Set surveys, product tours, and tooltips live.
Tag management: Can create and manage tags.
Outbound Full
Includes all Outbound Lite permissions plus:
Advanced workflows: Can manage outbound automation workflows.
Enhanced tools: Full outbound feature set.
Content Creator roles
Content Creator Lite
Draft creation: Can create and update draft Help Centre articles.
Basic knowledge access: Create and manage knowledge base content.
Personal tools: Access to personal macros.
Basic messaging: Can publish news.
This role is used for P&E for release notes, and Product Enablement.
Content Creator Full
Includes all Content Creator Lite permissions plus:
Publishing rights: Can manage and publish Help Centre articles.
Advanced management: Manage saved views and automation workflows.
Full content control: Complete knowledge base management.
This role is used for DSEs.
Technical Implementation
Specialised role for the technical setup of Intercom:
Developer access: Can access Developer Hub and manage integrations.
App management: Install, configure, and delete applications.
Settings access: Limited access to general and security settings.
Messenger configuration: Can access Messenger settings.
This role is used for P&E, specifically for during the Intercom implementation phase.
Reporting View-Only
Read-only reporting access:
No conversation access: Can view but not manage conversations.
Reports only: Limited to viewing and creating reports.
No system changes: Can't modify settings or configurations.
This role is used for the Support Director.
Align job roles to the permissions role
These are the typical job roles and the permission role that you'd require:
Job role | Permission role |
Central ops team | Administrator |
Support agents | Conversations |
Onboarding agents | Conversations |
Support Team Leads | Conversations manager |
CSMs | Outbound lite or full |
Digital CSM | Outbound lite or full |
Marketing | Outbound lite or full |
P&E (For release notes) | Content creator lite |
Product enablement | Content creator lite |
DSE | Content creator full |
Support director | Reporting view-only |
P&E during Intercom implementation phase | Technical implementation |
