Skip to main content

Access control

VoisX controls access with roles at two levels:

  • Organization: your company's workspace. It holds members, billing, security settings and all your projects.
  • Project: a set of agents, workflows, knowledge bases, channels and data. Each project has its own members.

Built-in roles​

Both levels use the same four roles.

RoleIn the organizationIn a project
OwnerEverything, including billing and deactivating the organization.Everything, including deleting the project and transferring it to another organization.
AdminMembers, roles, domains, security and billing.Manage the project, its members and settings.
ContributorBuild and deploy agents, edit the organization profile.Create and edit agents, workflows, knowledge bases and tools.
ViewerRead-only across the projects they can see.Read-only.

A project member with no role set is a Viewer.

Manage organization members​

Open Organization → People. From there you can invite people, change a member's role and remove members. Role changes and removals ask you to confirm.

Manage project members​

Open the project's IAM page. It has tabs for Members, Pending invites and Roles.

Custom roles​

When the built-in roles are too broad, create a custom role with only the permissions you want, for example "Billing read-only" or "Agent editor, no deploy".

  1. Open Organization → Roles.
  2. Under Custom roles, enter a name and an optional description, then click Add role.
  3. Tick the permissions the role grants. Changes save as you tick.
  4. Assign the role to members. You can also see every assignment on Organization → Role assignments.

Permissions combine a resource and an action:

ResourcesActions
Organization, Project, Agent, Workflow, Member, Analytics, Billing, Knowledge baseView, Create, Update, Delete, Execute, Invite, Export, Deploy

Deleting a custom role removes it from every member it is assigned to. This can't be undone.

note

Roles control what people can do in the console. They don't apply to a project's API keys. A key works only for its own project, and you can limit it to certain agents and website domains. See Authentication.

Verified domains​

Add your company's email domain to let colleagues find and join your organization, and to set up single sign-on.

  1. Open Organization → Domains and click Add domain.
  2. Enter the bare domain, such as example.com, without https:// or www.
  3. Add the TXT record the console shows to your domain's DNS.
  4. Click Verify now once the record is live.

After verification you can:

  • Turn on Global discovery, so people who sign up with a verified work email can find and request to join your organization. You approve them under Join requests.
  • See people who signed up with your domain but aren't members yet, and invite them.
  • Turn on Require org membership to flag those accounts as overdue to join. This is a status only and never blocks anyone's sign-in.

API keys​

A project API key lets your own code and the website widget call VoisX on behalf of one project.

  • A project can have several active keys, for example one per website channel.
  • Generate a key in Project → Settings → API keys, or for any project from Organization → API keys.
  • The full key is shown once. Copy it or download it as a .txt file straight away.
  • Revoking a key cuts off every application that uses it immediately.
  • You need the Contributor role or higher to generate or revoke keys.
  • For widget keys, restrict the key to your website's origins when you create it.

Keep keys on your server or in a secrets manager, never in a public repository. See the API reference for how to use a key.

Audit log​

Member joins, role changes, API key events and other administrative actions are recorded. See Organization → Audit log and Project → Settings → Audit log.

Was this page helpful?