Getting started
Roles and team access: who does what in the dashboard
Roles and team access: who does what in the dashboard
Unless keeps team management simple with three distinct roles, each designed for a specific type of user. Understanding these roles matters because they determine not just what someone can see, but also what they can do with the Customer Agent, the Team Assistant, and the audit trail. The right role assignment also supports your security posture, especially if you operate in a regulated sector.
The three access levels
Unless offers three user roles, each with a different scope of control:
- Admin: has all rights within a customer account. This includes user management, configuration changes, and access to every section of the dashboard.
- User: has everything except user management. Users can work with the platform’s features but cannot add, remove, or modify team members.
- Team Assistant only: can authenticate the browser extension but cannot see the dashboard at all. This role is designed for support agents who only need the Team Assistant in their helpdesk.
The distinction between User and Team Assistant only is important. A User can access the dashboard and manage content, while a Team Assistant only user is limited to the browser extension and has no dashboard visibility.
Managing team members
Adding a support agent
To add someone who only needs the Team Assistant, open Account and billing > Team and roles > Add user, then pick the Team Assistant only role. The user can authenticate the browser extension but will not see the dashboard.
Removing a user
Open the user’s profile and click Remove. The user loses access immediately, but their action history stays in the audit log. This is useful for internal reviews and SOC 2 evidence.
Plan limits
The number of users you can add depends on your plan. Flex includes 10 team seats, with unlimited seats available as an add-on module. Fixed includes unlimited seats. Check the Subscription and invoices page for the rest of the plan limits.
Access control principles
Unless applies strict access control principles across the platform:
- The customer has the sole right of granting access to anyone
- Unless employees have no access by default
- Passwords are always hashed and salted using bCrypt
- Data at rest and in motion is always encrypted using TLS with at least 128-bit AES encryption
- Data transport is over TLS using SHA-256 with RSA Encryption
These principles mean you control who gets in, and Unless cannot see your data unless you explicitly grant access.
Security features for the Team Assistant
The Team Assistant includes two security features that work alongside your role assignments:
- Limited host list: The extension uses a restricted list of allowed hosts and domains to ensure it only interacts with approved systems, reducing the risk of unauthorized access or data exposure.
- Role-based access: Users can only access Team Assistant features according to their assigned role (administrator, user, or team assistant).
External auditors
If you need to bring in an external auditor, you can create an external-auditor role in Team and roles with read access to Trust and Conversations only. This gives the auditor what they need without exposing the rest of the dashboard.
Best practices for role assignment
When setting up your team, consider the principle of least privilege. Document who has administrative access to the Unless dashboard, ensure role-based permissions align with least privilege, and plan for access revocation when team members change. Quarterly access reviews help verify that users still need their current access levels.
Conclusion
Role management in Unless is straightforward but carries real security weight. By assigning the right role to each person, you control who can configure the agent, who can only use the Team Assistant, and who can see the dashboard at all. Combined with the platform’s access control principles and the ability to remove users immediately, you can keep your workspace both functional and secure.