Predefined policies

Live Hub supplies the policies listed here, each of which grants a fixed set of roles. A user group carries one or more of them; see the predefined groups for which group carries which policy.

None of them can be edited or deleted.

A role ending in * grants every action on that resource: read, create, edit, and delete. A role ending in read grants only the first.

Configuration Administrator

The Configuration Administrator policy grants read-write access across the account's configuration.

Role Grants
livehub/bots/* Bot connections and speech providers
livehub/numbers/* Phone numbers
livehub/sipConnections/* SIP connections
livehub/teams/* Microsoft Teams connections
livehub/routingRules/* Routing
livehub/calls/* Call history
livehub/settings/*, livehub/accounts/delete Account settings, including deleting the account
livehub/accounts/create Creating an account
livehub/alarms/read Viewing active alarms and alarm history
livehub/alarms/thresholds/* Alarm thresholds
livehub/statistics/read Viewing statistics
livehub/campaigns/* Outbound automation
livehub/voiceTranslation/* Voice translation
livehub/aiFramework/* AI agents

Configuration Viewer

The Configuration Viewer policy grants the same access, read-only.

Role Grants
livehub/bots/read Viewing bot connections and speech providers
livehub/numbers/read Viewing phone numbers
livehub/sipConnections/read Viewing SIP connections
livehub/teams/read Viewing Microsoft Teams connections
livehub/routingRules/read Viewing routing
livehub/calls/read Viewing calls
livehub/settings/read Viewing account settings
livehub/statistics/read Viewing statistics
livehub/campaigns/read Viewing Outbound automation
livehub/voiceTranslation/read Viewing voice translation
livehub/alarms/read Viewing active alarms and alarm history
livehub/alarms/thresholds/read Viewing alarm thresholds
livehub/aiFramework/read Viewing AI agents

Call Data Manager

The Call Data Manager policy grants access to what was said and recorded on calls.

Role Grants
livehub/calls/* Call records, including deleting them
livehub/callTranscript/* Call transcripts
livehub/callRecording/* Call recordings

Call Control

The Call Control policy grants roles for acting on calls through the API rather than the portal.

Role Grants
livehub/bots/actions/dialout Placing outbound calls with the dialout API
livehub/sipConnections/actions/generateCode Generating a Click-to-call authentication code

Billing Administrator

The Billing Administrator policy grants read-write access in Billing, including adding credit.

Role Grants
livehub/accounts/actions/addCredit, livehub/billing/read Read-write in Billing, including adding credit

Billing Viewer

The Billing Viewer policy grants read-only access in Billing.

Role Grants
livehub/billing/read Viewing Billing, and the account and monthly balance in the top bar

Account Manager

The Account Manager policy grants roles for managing who can access the account: assigning users and API clients to user groups, and creating API client credentials. These roles are not Live Hub roles: they belong to Access control (IAM), which is why they are named differently.

Role Grants
AA/MANAGE_ACCOUNTS Managing accounts
AA/MANAGE_APPLICATIONS Managing API clients
AA/MANAGE_IDENTITIES Managing users
AA/MANAGE_PREDEFINED_USER_GROUPS Managing membership of the predefined user groups