Skip to main content
Permissions let you control how much access your end-clients have inside their PulsyAI subaccount — either platform-wide as a default for every new client, or on a per-client basis to override the default for specific accounts. The most common use case is restricting clients from editing agent prompts so they can’t accidentally break their own AI agents.

Where to find Permissions

Click Permissions in the left sidebar of your white-label admin, under the SETTINGS section. The page opens to the Permission Configuration view with two tabs at the top: Default permissions and Client permissions.
01 Permissionconfiguration

The two permission levels

Every subaccount in your white-labeled platform operates at one of two access levels: Read only — The subaccount can monitor their AI agents but cannot change anything. Inside their dashboard they only see three tabs:
  • Analytics — Aggregate performance metrics and KPIs for their agents.
  • Call Logs — The history of every call their voice AI agents have handled, with recordings and transcripts.
  • Conversations — The full history of every SMS thread their SMS AI agents have exchanged.
Everything else — prompts, call flows, knowledge bases, agent settings, integrations, SMS configuration, phone numbers — is hidden or locked from edit. They cannot modify their agents in any way. Read & write — Full platform access. The subaccount can view and edit every aspect of their AI agents, including prompts, call flows, knowledge bases, integrations, and all configuration.

Why use Read only

Read only is one of the most-requested features from PulsyAI resellers. The reasoning is straightforward: many end-clients are business owners who don’t have the technical chops to safely edit AI prompts. When they tinker with the prompt or call flow, they sometimes break the agent — the AI starts hallucinating, misroutes calls, or stops behaving correctly — and then they blame the reseller for an AI that “doesn’t work anymore.” Locking these clients into Read only gives them everything they need to validate the value of the AI for their business:
  • They see analytics — proof that the AI is generating ROI.
  • They see call logs — they can listen to recordings and review transcripts to confirm call quality.
  • They see SMS conversations — they can monitor what their SMS agent is saying to leads.
What they cannot do is touch the prompt or any operational settings. The reseller (you) retains full control over how the agent actually works, and clients can only observe the output. For technically capable clients, agencies operating under your brand, or any client you trust to manage their own configuration, Read & write is the right choice. Pick the level that matches the client’s competence and the level of hands-on support you want to provide.

What a Read only client sees

When a client is set to Read only, their dashboard inside any AI agent they own collapses to three tabs only:
03 Whatreadonlyusercansee
The three tabs they retain are observability-only:
  • Analytics — The Assistant Dashboard with minutes used, amount of calls, revenue, call status breakdowns, call distribution charts, and the most recent calls in the selected date range. The client can adjust the date range and click Configure Analytics to set how revenue is calculated, but they cannot edit the agent itself.
  • Call Logs — The full call history for the voice agent, with recordings, transcripts, durations, and call statuses. The client can listen, read, and review — they cannot edit any call data or the agent producing the calls.
  • Conversations — The same observability for SMS agents — full conversation threads with the client’s leads or customers.
Every other tab is hidden entirely from the client’s view: Call Flows, Knowledge, SMS Configuration, Integrations, Transfers, and any other editing-related surface inside the agent. The client cannot see prompts, edit scripts, modify knowledge base content, change integration credentials, or alter call routing — there is no path in the UI for them to reach those screens. The same restriction applies to the left sidebar of their account. A Read only client does not see Agent Templates, integration shortcuts, phone number management, or any other reseller-level surface in their navigation. The only navigation available to them is the path to their AI agents and the three observability tabs within each one. Their personal Settings page remains accessible — they can still update their profile, change their password, and manage their basic account preferences — but the API keys section inside Settings is hidden from Read only clients. They cannot view or regenerate API keys for their account. This is the point of Read only: your client gets the visibility they need to validate the agent’s performance, listen to actual calls, and report on outcomes — without any ability to break the configuration you’ve put in place for them.

Set the default permission level

The Default permissions tab sets the access level that automatically applies to every new subaccount created on your branded platform.
04 Defaultpermission
Click the card matching the level you want as the default — Read only or Read & write. The selection is saved immediately. Every new subaccount created from this point on will start at this permission level. Changing the default does not retroactively affect existing subaccounts — only new ones created after the change. To change the level of existing subaccounts, use the Client permissions tab.

Override permissions per client

The Client permissions tab lets you set the access level for individual subaccounts, overriding the platform-wide default.
02 Clientpermissions
The list shows every subaccount you have, with their current permission level visible on the right side of their card (Read only or Read & write). To change a specific client’s permission:
  1. Find the client using the Search clients field — search by name or email.
  2. Click the client’s card to expand it. The permission level options appear inside.
  3. Click either Read only or Read & write to set the level for this specific client.
Changes save immediately. There is no separate save button. The client sees the new permission level the next time they refresh their browser — there is no logout or re-login required, and no notification is sent to the client about the change. Per-client overrides are useful when most of your clients should be Read only (for example, restricting your default to Read only) but you have a handful of agency partners or technical clients who need full access — set those specific clients to Read & write while everyone else stays on the default.

Testing Read only permissions correctly

Impersonating a Read only subaccount from your admin account does not restrict your view. When you click Select on a Read only subaccount in the Clients page, you see the platform as the admin operating on their behalf — which means you still see all tabs and can edit everything. This is by design: as the reseller, you need full edit access to support and maintain your clients’ agents regardless of their own permission level.To actually verify what a Read only client sees, log in directly using that subaccount’s credentials in a separate browser session or incognito window. Only a direct login enforces the permission level — impersonation always grants you full admin visibility.

Next step

Agent Templates

Build pre-configured agent templates your end-clients can deploy in seconds.