Predefined policies
Live Hub supplies the policies listed here, each of which grants a fixed set of roles. A user group carries one or more of them; see the predefined groups for which group carries which policy.
None of them can be edited or deleted.
A role ending in * grants every action on that resource: read, create, edit, and
delete. A role ending in read grants only the first.
Configuration Administrator
The Configuration Administrator policy grants read-write access across the account's configuration.
| Role | Grants |
|---|---|
livehub/bots/*
|
Bot connections and speech providers |
livehub/numbers/*
|
Phone numbers |
livehub/sipConnections/*
|
SIP connections |
livehub/teams/*
|
Microsoft Teams connections |
livehub/routingRules/*
|
Routing |
livehub/calls/*
|
Call history |
livehub/settings/*, livehub/accounts/delete |
Account settings, including deleting the account |
livehub/accounts/create
|
Creating an account |
livehub/alarms/read
|
Viewing active alarms and alarm history |
livehub/alarms/thresholds/*
|
Alarm thresholds |
livehub/statistics/read
|
Viewing statistics |
livehub/campaigns/*
|
Outbound automation |
livehub/voiceTranslation/*
|
Voice translation |
livehub/aiFramework/*
|
AI agents |
Configuration Viewer
The Configuration Viewer policy grants the same access, read-only.
| Role | Grants |
|---|---|
livehub/bots/read
|
Viewing bot connections and speech providers |
livehub/numbers/read
|
Viewing phone numbers |
livehub/sipConnections/read
|
Viewing SIP connections |
livehub/teams/read
|
Viewing Microsoft Teams connections |
livehub/routingRules/read
|
Viewing routing |
livehub/calls/read
|
Viewing calls |
livehub/settings/read
|
Viewing account settings |
livehub/statistics/read
|
Viewing statistics |
livehub/campaigns/read
|
Viewing Outbound automation |
livehub/voiceTranslation/read
|
Viewing voice translation |
livehub/alarms/read
|
Viewing active alarms and alarm history |
livehub/alarms/thresholds/read
|
Viewing alarm thresholds |
livehub/aiFramework/read
|
Viewing AI agents |
Call Data Manager
The Call Data Manager policy grants access to what was said and recorded on calls.
| Role | Grants |
|---|---|
livehub/calls/*
|
Call records, including deleting them |
livehub/callTranscript/*
|
Call transcripts |
livehub/callRecording/*
|
Call recordings |
Call Control
The Call Control policy grants roles for acting on calls through the API rather than the portal.
| Role | Grants |
|---|---|
livehub/bots/actions/dialout
|
Placing outbound calls with the dialout API |
livehub/sipConnections/actions/generateCode
|
Generating a Click-to-call authentication code |
Billing Administrator
The Billing Administrator policy grants read-write access in Billing, including adding credit.
| Role | Grants |
|---|---|
livehub/accounts/actions/addCredit, livehub/billing/read |
Read-write in Billing, including adding credit |
Billing Viewer
The Billing Viewer policy grants read-only access in Billing.
| Role | Grants |
|---|---|
livehub/billing/read
|
Viewing Billing, and the account and monthly balance in the top bar |
Account Manager
The Account Manager policy grants roles for managing who can access the account: assigning users and API clients to user groups, and creating API client credentials. These roles are not Live Hub roles: they belong to Access control (IAM), which is why they are named differently.
| Role | Grants |
|---|---|
AA/MANAGE_ACCOUNTS
|
Managing accounts |
AA/MANAGE_APPLICATIONS
|
Managing API clients |
AA/MANAGE_IDENTITIES
|
Managing users |
AA/MANAGE_PREDEFINED_USER_GROUPS
|
Managing membership of the predefined user groups |