Why it matters
Messaging permissions should match each team member's responsibilities. A user who only needs to work with recruiting contacts, for example, may not need access to customer-facing channels or permission to create and update campaigns.
Whippy gives administrators two complementary ways to manage this risk:
Roles and permissions control the product areas and actions a user can access, such as viewing contacts or creating and updating campaigns.
Channel access controls which messaging channels and related conversations a user can see and use.
Using both controls together helps protect customer data and prevent accidental sends.
Key Concepts
Custom role: A role created for a specific job function. It contains only the permissions that person needs.
Least privilege: Giving a user the minimum access required to complete their work.
Campaign permissions: Permissions that control whether a user can create, update, or delete campaigns. Updating includes campaign settings, audience configuration, and campaign status where available.
Contact permissions: Permissions that control whether a user can create, read, update, or delete contact records.
Channel access: Access to a specific SMS, email, WhatsApp, voice, or other connected channel and its conversations.
Channel permissions: Controls that determine what a user can do within an assigned channel. Available options depend on the channel and workspace configuration.
Before you begin
You need permission to manage roles, users, and channels. If these settings are not available to you, ask a Whippy administrator to make the changes.
Step 1: Create a restricted custom role
Open Settings > Users and teams.
Select the Roles tab.
Click Add role.
Enter a clear role name, such as
Recruiter - Restricted Messaging.Add a description explaining who should receive the role and what work they are expected to perform.
Select only the permissions required for that work.
Click Add role to save it.
Avoid Select all permissions unless the role genuinely requires access to every available action.
Step 2: Remove unnecessary campaign permissions
If the user should not build or launch campaigns, do not include the following permissions in their custom role:
Campaigns - Create
Campaigns - Update
Campaigns - Delete, unless deletion is part of their responsibilities
The Update permission can cover campaign settings, audience configuration, and campaign status where available. Review all roles assigned to the user because access granted by another role may still allow campaign actions.
Step 3: Limit access to contacts and other data
Review the role's contact and data permissions and remove anything the user does not need. Contact permissions include:
Read Contact: View, search, filter, count, and open contact records.
Create Contact: Create contact records.
Update Contact: Edit contact records and related contact actions.
Delete Contact: Delete or archive contact records where available.
For example, a user who does not need to browse the contact database should not receive Read Contact. A user who only needs to view contact information may need Read Contact, but not Create, Update, or Delete.
Roles control access to product areas and actions. They do not necessarily limit a user to an arbitrary subset of individual contact records. Use channel access to limit which channel conversations and messaging activity the user can access.
Step 4: Assign the role to the user
Open Settings > Users and teams.
Select the Users tab.
Find the user and open their actions menu.
Select Assign role.
Select the restricted custom role.
Review any other roles assigned to the user and remove roles that grant unnecessary access.
Ask the user to refresh Whippy if the new permissions do not appear immediately.
Step 5: Restrict channel access
Only give the user access to channels relevant to their work.
Open Settings > Channels.
Find the channel you want to manage.
Open the channel's actions menu and select Edit channel.
Open the Users tab.
Find the user and open their actions menu.
Choose the appropriate option:
Permissions: Review or adjust what the user can do in that channel.
Remove from channel: Remove their ability to see or use that channel.
Disable user: Temporarily block the user. Depending on your workspace configuration, disabling a user may affect access beyond the selected channel.
Where the channel's permission options support it, restrict the user's ability to send or respond. If the user should have no access to the channel, remove them from it instead.
To prevent a user from sending messages while allowing them to retain other Whippy access, remove them from every messaging channel they should not use or remove their send/respond permissions where supported. To prevent all access to Whippy, disable the user entirely.
Changes to channel access apply immediately.
Example: Separate recruiting outreach from customer messaging
A recruiting team member needs to contact job candidates but should not send messages to customers.
To reduce the risk of an audience mix-up:
Create a restricted recruiter role with only the contact and messaging permissions required for recruiting work.
Remove Campaigns - Create and Campaigns - Update if the recruiter should not build or launch campaigns.
Assign the recruiter only to the recruiting channel.
Remove the recruiter from customer-facing channels.
Review their channel permissions and restrict sending or responding where supported.
If the user temporarily should not send any messages, remove them from all messaging channels or remove their send/respond permissions where supported. Disable the user entirely only if they should have no access to Whippy.
This setup prevents the user from accessing customer-facing channel conversations and reduces the actions available to them elsewhere in Whippy.
Review a campaign safely before sending
Users who are allowed to create and send campaigns should complete these checks before every bulk send:
Save the campaign as a draft. Do not send while the audience or message is still being prepared.
Review the audience. Open View audience and confirm that the included contacts, lists, tags, segments, and filters are correct.
Review exclusions. Open View excluded audience and confirm that exclusions and audience safety settings are working as intended.
Check the sending channel. Confirm the campaign is being sent from the correct SMS number, email address, or WhatsApp sender.
Preview the message. Check the copy, variables, attachments, links, sender information, and formatting.
Send a test message. Send the test to yourself or a teammate and verify it before proceeding.
Confirm the audience size. Investigate an unexpectedly large audience before sending.
Use batch sending for large audiences. Smaller batches help control send volume and give your team more time to identify an issue.
Use the final confirmation carefully. When Whippy asks you to type
confirm, treat it as the final approval that the channel, audience, and message are correct.
Tips and Best Practices
Create roles around job responsibilities, such as Recruiter, Support Agent, or Campaign Manager.
Give users the least access they need and add permissions only when a business need is confirmed.
Review all roles assigned to a user; permissions from multiple roles may combine.
Keep channel user lists small and relevant.
Review role and channel access whenever someone changes teams or responsibilities.
Use separate channels, lists, tags, or segments for operationally different audiences such as candidates and customers.
Require an internal review for large or sensitive campaigns, even if the sender has permission to launch them.
Use drafts, audience previews, test messages, and batching as standard campaign controls.
Troubleshooting
Issue | Possible cause | Fix |
A user can still create or update campaigns | Another assigned role grants Campaigns permissions | Review every role assigned to the user and remove unnecessary Create or Update access. |
A user can see a channel they should not access | The user is still listed in the channel's Users tab | Remove the user from that channel. |
A user can still see activities from other channels | Their role includes Channels - View All Activities | Remove View All Activities if it is not required. |
A user can view more contact data than expected | Their role includes Read Contact | Remove Read Contact if they do not need access to the contact database. |
A user should temporarily stop using a channel | They still have active channel access | Remove them from the channel or remove their send/respond permissions where supported. Disable the user entirely only if they should have no access to Whippy. |
Permission changes do not appear | The user has not refreshed, has another role, or still has channel-specific access | Review all assigned roles and channels, then ask the user to refresh Whippy. |
A campaign audience is unexpectedly large | A broad list, tag, segment, upload, or filter was selected | Do not send. Review View audience, inclusions, exclusions, and filters until the count is correct. |
