> For the complete documentation index, see [llms.txt](https://docs.pascom.net/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.pascom.net/en/setup/user/role.md).

# Permissions

Permissions allow you to assign Users, Teams, Devices and Workstation (locations) diverse roles and functions.

## Training Video

{% embed url="<https://www.youtube.com/watch?v=WVQuH8x7CXc>" %}

## Concept

Users, devices, teams and even locations can be assigned one or more permissions. Permissions themselves can be assigned with functions and roles, which can be used to control telephony relevant tools such as, for example, whether or not a user is permitted to pickup calls from other users.

Permissions are set up under **Users** > **Permissions**.

A special **All Users** permission is available which is assigned to all users, devices, teams and locations per default.

A common use case (and our recommendation) is to create a permission per department or team. *For example, it is often wished that a user can only pickup and see calls in the PASCOM app that are from within their own department. To do this, simply remove the xmpp.group property from the All Users permission and assign it to a new permission e.g. Support and make all support employees members of the permission group.*

## The permission "All"

By default, every PASCOM telephone instance has a permanently implemented permission called "All". This permission cannot be removed. However, you can adjust them that they no longer contain permissions or assignments.

*The permission "All" should make it easier for beginners to deal with user permissions and, by default, enables the visibility of users and teams in the PASCOM app*

## Creating permissions

permissions can be found under **Users** > **permissions**.

To create a permission, click the **Add**.

Provide the permission with a name which corresponds to the intended permission assignment or function / permission. Optionally, under the Description field you can also enter additional relevant information which provide insight into the purpose of the permission.

### Activate automatic assignment

In the base settings of each permission, you have the option of having assignments carried out automatically. This is a great feature to significantly reduce maintenance.

A permission can automatically assign users, teams, locations and devices.

<figure><img src="https://2713225-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FVIw0BpSv358R2Pr2HflD%2Fuploads%2Fgit-blob-7f817ccae67c2499cb351eea5621b366bd8338e4%2Frole_basedata.en.PNG?alt=media" alt="permission Basesettings" width="45%"><figcaption></figcaption></figure>

**How does it work exactly?**

If you activate a setting for automatic assignment, the corresponding tab disappears from the tab bar and the assignment is made automatically.

*example:*\
If you activate the automatic assignment of users, **all** existing users on the PASCOM telephone system, are assigned to this permission .

If you deactivate a setting for the automatic assignment, the corresponding tab appears again in the tab bar and you can manually assign the corresponding elements to the permission.

{% hint style="success" %}
If automatic assignment is activated, newly created elements such as e.g. Users and teams, will be automatically assigned.
{% endhint %}

### The permission Types explained

Permissions can have one or more permission types, also known as roles, added to them. Each role type offers differing functionality.

| Role Type        | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | Impact                        |
| ---------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------- |
| xmpp.supervisor  | Users with this role can manage all user calls. This is important when using the TAPI.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | Users                         |
| location.group   | This role determines which users can log into which locations. If this role is not configured, every user will be able to log into every work location. Once such a role has been added, users who are not members of a location.group role will no longer be able to login to locations.                                                                                                                                                                                                                                                                                                                   | Users, Locations              |
| pickup.group     | All members of this role group are permitted to pickup incoming calls to other group members. This can be done by either using /\*8 on a desktop phone or by using the PASCOM app.                                                                                                                                                                                                                                                                                                                                                                                                                          | Users, Call Groups and Queues |
| redirect.choice  | An identity with this role type will never be redirected by a server based call forwarding, but rather always calls the destination directly.                                                                                                                                                                                                                                                                                                                                                                                                                                                               | Users                         |
| xmpp.group       | All identities assigned with the role type xmpp.group will be amalgamated into a XMPP shared group. Therefore, within the PASCOM app contact list, these persons no longer need to add one and another but are rather immediately visible to each other. Should you assign the xmpp.group role type to the *All Users* role, then all users will always be able to see each other in the app.                                                                                                                                                                                                               | Users                         |
| redirect.group   | All users with this role are permitted to set call forwarding for other users (via [Function Codes](/en/reference/featurecodes.md))                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | Users                         |
| profile.personal | All users in this role have the right to create, edit and delete their own app profiles.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | Users                         |
| chat.allowed     | <p>Users with permission can use the full chat functionality.<br><br><strong>Users without permission</strong><br>- can still chat with people who have chat rights.<br>- can continue to chat in groups if they were invited AND at least one participant has permission.<br>- can leave a group.<br>- cannot create a new group.<br>- cannot add other people to a group.<br>- cannot configure the group (e.g., make it public).<br>- cannot chat with people if no one in the group/room has chat permissions.<br>- will receive an error message when trying to send a message without permission.</p> | Users                         |

Now you can assigned users, teams, devices and / or locations to your newly created permission - depending of course what the defined role type affects.

## Example Usage

### Visibility in the App

Should you wish to make teams visible in the [Desktop and Mobile App](/en/operations/clients.md), a permission with the role type **xmpp.group** is required.

Example:\
Under **Users** > **permissions** > **Add** add a new permission with the name "Support-Team".\
Under the **Role types** tab, add the ***xmpp.group*** role type to the role.\
Under the **Users** tab, add all "Support" users.\
Under the **Teams** tab, add the "Support" team.\
Click **Save** and apply the changes. *Now all support users will see their own "Support Team" contact list within the PASCOM app and under the contacts filter drop down "Teams", the "Support" queue will also be visible.*

Should you wish to see who is calling with whom within the app, then you will need to the set the ***sys.xmpp.properties.roster.shownumbers*** property setting to "true" within the PASCOM cloud phone system web UI. *(Available since PASCOM 17.08)*

### Pickup

In principle, every user can use the /\*8 code to pick up calls from any other user at least until a permission with the role type "pcikup.group" has been added. From this point, the pickup permissions must be explicitly defined.

Within a team, it is possible to determine which employees receive inbound call PASCOM app pickup notifications.

If the [Team](/en/setup/teams/configuration.md#pickup-notifications) pickup configuration options are not able to include all to be permitted users, you will need to create a pickup group.

With a pickup permission with the type **pickup.group** it is also possible to configure users to be able to pickup incoming external and internal calls from one another.

Example:\
Under **Users** > **permissions** > **Add** add a new permission with the title "Pickup Group".\
Under the **Role Type** tab, add the type ***pickup.group*** to the role.\
Under the **Teams** tab, assign the desired team.\
Under the **Users** tab, assign the desired users.\
Click **Save** and apply the changes.

*Finally, you can specify in the* [*Team*](/en/setup/teams/configuration.md#pickup-notifications) *to which the pickup permission belongs, that the pickup group should be used as the control option.*

### Penetrate Call Forwards

If user 'A', despite a call forwarding being activated wishes to directly reach internal user 'B' without the call forwarding coming into affect, a permission with the role type **redirect.choice** is required. Each user with this permission breaks through (penetrates) the call forwarding rule and will be put directly through to the selected extension.

Example:\
Under **Users** > **permissions** > **Add** add a new permission with the title "Boss Redirect".\
Under the **Role types** tab, add the role type ***redirect.choice*** to the role.\
Under the **Users** tab, add the user "Boss".\
Click **Save** and apply the changes.\
Now the user "Boss" can always directly reach any user despite any active call forwards.

### TAPI

Should you wish to use the [PASCOM TAPI](/en/operations/clients/tapi-installation.md) under your windows environment, then a separate permission is required.

For this purpose, create a permission with the role type **xmpp.supervisor** and in the case of a Terminal Server scenario, assign a user via which telephony should be managed.

Example:\
Under **Users** > **permissions** > **Add** add a new permission with the title "TAPI-User".\
Under the **Role types** tab, add the role type ***xmpp.supervisor*** to the role.\
Under the **Users** tab, add the user "Superuser".\
Click **Save** and apply the changes.

### Flexible Workstations / Locations

Should your employees not have fixed permanent workstations within your company or certain employees regularly change their [work locations](/en/setup/user/user-concept.md) (e.g. branch locations or HomeOffice) it is advisable to not assign the corresponding PASCOM cloud phone system devices directly to the users but rather to a [Location](/en/setup/user/user.md#using-locations).

Per default, each PASCOM cloud phone system user can log into any location. Should you wish to prevent this and only allow users to certain locations, a permission with the role type **location.group** is required.

This configuration is necessary for each user wishing to flexibly user different locations.

Example:\
Under\* **Users** > **permissions** > **Add** add a new permission with the title "Location Office Internship".\
Under the **Role types** tab, add the role type ***location.group*** to the role.\
Under the **Users** tab, add the user "Office Intern".\
Under the **Locations** tab, add the available / permitted locations.\
Click **Save** and apply the changes.\
*Now the user "Office Intern" can only log into the assigned locations.*

### Setting Call Forwards

If a user should have the permission to set call forwards for other users using [Function Codes](/en/reference/featurecodes.md), a permission with the role type **redirect.group** is required.

Example:\
Under **Users** > **permissions** > **Add** add a new permission with the title "Call Forwarding".\
Under the **Role Types** tab, add the type ***redirect.group*** to the role. Under the **Users** tab, add the user "Secretary".\
Click **Save** and apply the changes.

*Now the user "Secretary" will have the ability to use the function codes to set up call forwarding for other users. For example, should it be necessary, to set up a forwarding to the central switchboard (ext. 100) for the user with the extension 15 they can use the function code \*7415#100.*

### Personal app profiles

If a user is to have the right to manage their own app profiles, a permission with the **profile.personal** role type is required. This allows members with this permission to create, edit and delete app profiles. Users without this permission type can only use the **default** profiles in the PASCOM app.

{% hint style="success" %}
The role type **profile.personal** is not set automatically for custom permissions. Please remember to set the permission if needed.
{% endhint %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://docs.pascom.net/en/setup/user/role.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `build a script that syncs our docs to a CMS` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
