Access and visibility policy
The portfolio setting that decides which conversations, contacts and sections each role sees. A closed section leaves the menu and will not open from its address either.
Last updated: September 30, 2026
The portfolio setting that decides which conversations, contacts and sections each role sees. A closed section leaves the menu and will not open from its address either.
Last updated: September 30, 2026
The access and visibility policy decides what each role on your team sees in the panel. The role says what a person can do; the policy says what they can see. Because the two are kept apart, you can let an agent reply to messages while limiting their field of view to their own conversations.
⚠️ Note: only people who can assign conversations may write the policy, that is the portfolio owner and its administrators. If the portfolio is scheduled for deletion, the policy cannot be saved.
Per role, the policy decides three things:
The policy belongs to the portfolio: it applies identically across every account in it. There is no per-account policy.
✅ A closed section does not merely disappear from the menu: its page will not open either. Someone typing the address and someone arriving from a notification get the same result. Hiding a menu item is not security on its own; the gate sits on the page and on the data itself.
The policy is configured separately for editor, agent and viewer. Owners and administrators are outside it: there is no point in the people who run the portfolio hiding things from themselves, so they always see everything.
On the screen each role has its own block, with a line underneath the heading saying what the role is for:
The Conversations list offers three options:
The scope also binds the inbox tabs. For a restricted agent, the "Unassigned" tab cannot show more than the policy allows. The same rule applies when opening a conversation from its address, from a notification link, or from a contact card.
The Contacts list offers two options:
When contact scope is limited to "their own conversations", their own means the conversations assigned to them. Even if conversation scope is "all conversations", a narrowed contact scope still produces only the contacts of conversations assigned to that person.
Under Sections there are six checkboxes:
Clearing a checkbox closes that section for everyone in that role.
⚠️ Note: the inbox is not in the list and cannot be closed. It is the reason a team member opens the panel at all. Settings is not in the list either; its contents are already filtered by role permissions.
Opening a section requires two conditions together: the role must hold the permission, and the checkbox must be ticked. That is why ticking Reports for an agent does not open it — the agent role has no permission to view reports. In the same way Insights and My profile and Publishing exist only on Instagram accounts; on a WhatsApp account the section stays hidden even with the box ticked.
If you never touch the policy, these defaults apply:
Conversations: all conversations in the account. Contacts: all contacts in the account. Sections: Automations, My profile and Publishing, Reports, Media and Contacts are on; Insights is off.
Conversations: only assigned to them. Contacts: only contacts from their own conversations. Sections: Media and Contacts are on; Automations, My profile and Publishing, Insights and Reports are off.
Conversations: all conversations in the account. Contacts: all contacts in the account. Sections: Automations, Reports, Media and Contacts are on; My profile and Publishing and Insights are off.
The defaults are aligned with what each role can actually do: showing a screen that nobody in that role can touch was only misleading.
Further down the same page is the Assignment of new conversations section: whether an incoming conversation is assigned automatically (no assignment / balanced / always the same person) and the maximum number of open conversations per person. They share a page because both answer the same question: who handles what.
The policy you save applies across every account in the portfolio and takes effect the next time someone opens a page; nobody has to sign in again.
The policy changes visibility alone: it removes nobody from the team and deletes no data.
An online shop runs two agents and has an intern as editor.
Set the policy once and everyone who joins the team afterwards starts with the right field of view on day one.
Was this article helpful?