Cloud, Services and Security

Who Sees What in the Control Panel? Users and Permissions

Users and permissions determine who can enter the PBX control panel and what they may see and change. The guiding principle is least privilege: each person gets exactly what they need for their job, and no more.

User PermissionsRolesAccess PermissionsRolesLeast PrivilegeMinimal Permission

Reading time: about 8 minutes

Why you need separate users

In many offices, there is a single password for the control panel at first, and everyone uses it. That's convenient, until something changes and nobody knows who changed it. Or until an employee leaves, and then the password has to be replaced and everyone else has to be told.

When each person has their own user, with a personal name and password, you can give each one different access, know who did what, and block one person without disturbing the others. It's the difference between one key passed from hand to hand and a personal key for each employee.

This is especially true for a phone system, because the control panel controls sensitive things: where calls go, who hears recordings, and which number shows up when you call out. One mistake in a setting can leave the office without a phone.

What a permission is

A permission is the answer to the question "Is this person allowed?" In a phone system control panel, these questions usually fall into three levels:

  • No access — the screen doesn't appear for them at all.
  • View only — can look, for example at the call log, but can't change anything.
  • View and edit — can edit settings, add and delete.

In many systems, permissions are given by screen or by area: call log, recordings, extensions, menus, numbers, accounts. This way you can give a secretary access to the call log without letting her touch the IVR menu.

It's worth knowing that in some systems there are differences even within a single screen. For example, you can see the list of extensions without seeing their passwords, or see a call in the log without hearing its recording. The more detailed the permissions, the easier it is to give each person exactly what they need.

The principle: minimal permission

In the world of information security, there is an old rule called minimal permission (Least Privilege): each person gets only the permissions they need to do their job, and no more. Not "just to be safe," and not "because they might need it one day."

The reason is simple. Every unnecessary permission is another open door. If an employee's password leaks, the damage is limited to what that employee is allowed to do. If an employee makes a mistake, the mistake is limited to what they can change. And someone who doesn't need to hear recordings of calls with customers simply doesn't hear them.

It's important to understand that this isn't a matter of trust. Even a completely trustworthy employee can click the wrong button, or fall for a fake email. Minimal permission protects them too.

In practice, this principle comes down to one standing question that the system administrator asks every time someone requests a permission: What does this person need to do, and what is the minimum that lets them do it? If the answer is "to view," you don't grant "to edit."

Common roles and what each one needs

Instead of thinking about each person separately, it's easier to think in terms of roles. Here is a breakdown that suits many offices, as a starting point:

RoleWhat they usually needWhat they usually don't need
System administratorEverything, including user management—
Office managerCall history, extensions, business hours, messagesBilling, user management
Call center supervisorActive calls, queues, call listeningNumbers, routing, billing
Receptionist / secretaryCall history, possibly a voicemail boxRecordings, settings, routing
AccountingInvoices and balanceRecordings, telephony settings

The table is an example, not a rule. In a small nonprofit, one person fills three roles, and a large call center may have ten kinds of staff. What matters is to ask about each permission: does this person really need it?

One more note: it's a good idea to write this breakdown on a single page and keep it. When a new employee arrives, there's no need to think it through again. You look at the page and open what's written next to their role.

The most sensitive permissions

Some permissions are worth thinking about twice before you grant them:

  • Call recordings — they contain personal information about customers and employees. See also Call Recording and Privacy.
  • Number routing — a wrong change sends all incoming calls somewhere else, or nowhere.
  • Listening to live calls — an important tool for training, but also very sensitive. Only for managers whose role requires it.
  • Outgoing calls and international destinations — a loose setting here can cost a lot of money, as explained in the article on telephony fraud.
  • User management — anyone who can create users can give themselves any permission. This is the most sensitive permission of all.

Records: who changed what

One of the great advantages of personal users is being able to know who did what. Many systems have an action log (Audit Log) that records every change: who made it, when, and what it was before the change.

This log isn't meant for finding someone to blame. It's meant for fixing things fast. When calls suddenly go to the wrong place, knowing that the change was made yesterday at four in the afternoon, in a particular menu, saves hours of guessing. And if the change was made on purpose, you can ask the person who made it why. Maybe they had a good reason.

All of this works only if each person has their own user. With a shared password, the log will only say "someone from the office."

When an employee joins, changes roles or leaves

Most permission problems don't arise on day one, but over time. An employee received a temporary permission for a project, and the project ended. A receptionist moved to accounting and kept her old permissions. That's how, after a few years, everyone has everything.

A simple procedure prevents this:

  1. New employee — create a personal user with the permissions of the role, not "the same as Yossi's."
  2. Change of role — remove the old permissions first, and only then add the new ones.
  3. Departure — block or delete the user on the day they leave, not "when there's time."
  4. Periodic review — once every six months, go over the list of users and ask: who is this, and what do they need?

The fourth step is the one everyone forgets, and it's the one that finds the user of an employee who left two years ago and is still active.

Passwords, IP addresses and layers of protection

Permissions determine what a user may do after logging in. Other layers determine who can log in at all:

  • A strong, personal password — long, not shared, and not the same password used elsewhere.
  • Restriction by IP address — you can require that a user log in only from certain addresses, for example only from the office. That way even a leaked password isn't enough. This works especially well when the office has a static address.
  • Two-factor authentication — an additional code sent to a phone or email at login.

No single layer is perfect. Together, they make unauthorized access very difficult.

Employees who don't need a user at all

It's worth remembering that most employees don't need to log in to the control panel at all. Someone who only answers the phone and transfers calls does it from the phone itself. An extension is not a user in the control panel, and vice versa.

Every user you don't create is a user you don't have to manage, whose password you don't have to remember, and who can't leak. That, too, is minimal permission.

Common mistakes

  • "Give him everything so he doesn't get stuck" — this is the most tempting and most dangerous shortcut. It's better to add a permission when it turns out to be needed than to remove it after something has happened.
  • One user for an outside vendor who stays forever — a technician or consultant who was given access for setup needs a temporary user, closed when the work is done.
  • A password written on a note next to the computer — anyone who walks by becomes the system administrator.
  • No backup administrator — when the only administrator is on vacation and something breaks, no one can fix it.
  • Forgetting to update after a change of role — the old permissions stay, and the new ones are added on top.

An example from the field

The Tiferet Shmuel yeshiva set up a single control panel user a few years ago and gave the password to the gabbai, the secretary and a student who helped with the setup. One day, incoming calls started arriving at the dining room extension. No one knew who had changed it, or why.

After the incident, they sorted things out: the gabbai got a user with access to business hours and messages. The secretary got access to the call history and the voicemail boxes. The student, who hadn't been helping for a long time, didn't get a user. The routing itself is changed only by the administrator, after a short talk with support.

Since then, when something changes, it's clear who could have changed it. That alone prevents most mistakes.

Multiple customers and resellers

In phone systems that serve several organizations, there's another layer of permissions: who sees which organization. A reseller who manages dozens of customers needs to see all of them, but each customer should see only itself. This structure is covered in more detail in the article on multi-tenant management.

The principle is the same: everyone sees what belongs to them, and no more. The difference is only in the level — not screen versus screen, but organization versus organization.

How it works with us at Kesher

The Kesher control panel has a Users and Permissions screen, where you create a user for each person and set what they can see and what they're allowed to change.

You can also restrict login by IP address, so that a user can log in only from addresses you've approved, for example only from the office.

Two-factor authentication at login is in development on our side and isn't available yet.

Resellers have customer management in the control panel, so each reseller sees their own customers. And if you're not sure which permission to give to whom, you can contact us. Every question is answered by a person, and every screen has an illustrated guide.

FAQ

Can I let an employee see only the call history?

In systems where permissions are granted per screen, yes. That's exactly the purpose: to give access to what's needed, and not to the rest.

What's the difference between a user and an extension?

An extension is a phone that receives and makes calls. A user is a person who logs in to the control panel to manage settings. Most employees have an extension, but don't need a user.

How many administrator users do I need?

As few as possible, but not just one. It's a good idea to have two, so that if one isn't available or forgot the password, someone else can handle things.

What do you do when an employee leaves?

Block or delete their user on the day they leave. If they knew any shared password, change it.

Can one password be used for the whole office?

It's possible, but not recommended. You can't tell who changed what, and you can't block one person without affecting everyone.

Why restrict login by IP address?

Because even if a password leaks, anyone trying to log in from a different address is blocked. It's an additional layer of protection, simple and effective.

Does minimal permission indicate a lack of trust?

No. It also protects the employee: from their own mistakes, and from a situation where someone else uses their password.

How often should I review the list of users?

Once every six months is a good habit, and also whenever an employee leaves or changes roles.

What do I do about an outside technician or consultant?

Create a separate user for them, with the permissions they need for that specific job, and close it when the job is done. Don't give them the office manager's password.

What happens if I gave too little permission?

The employee will discover that something is missing and ask for it. That's a much better situation than the reverse, where no one is sure who is allowed to do what. You add the missing permission, and make a note that this role needs it.

Back to the Knowledge Center — all terms

Want to hear how it would work for you?

Tell us how your phones work today — how many calls, who answers, what gets in the way — and we'll get back to you with an organized proposal.

Leave your details and we'll get back to you
077-921-9000