Product updateSecurityTeam access

Read-only viewer roles for safer team access

The ZenTalk teamAugust 27, 20266 min read

Not everyone who needs to see your conversations should be able to change them. A new manager watching a trainee, a client checking on their account, a compliance reviewer doing an audit: each of them needs a window into the work, not a hand on the controls. ZenTalk now ships a read only Viewer role that gives exactly that, visibility without the risk of a stray reply, edit, or deletion.

The short version

The Viewer role lets a person see the sites, visitors, and inbox you assign to them, and nothing else. Viewers cannot reply, edit a record, change settings, or take any write action. The block is enforced in two places at once, the API and the realtime layer, so there is no side door. It is the safe way to give managers, trainees, clients, auditors, and QA reviewers a look inside.

The problem with sharing access

Most teams solve the "let them see it" problem badly. They either hand out a full agent login, which means the new person can accidentally message a customer or delete a lead, or they screenshot conversations into a chat thread, which is slow, leaky, and always out of date. Neither is safe and neither scales.

The people who need visibility usually have no business writing anything at all. They are watching, learning, checking, or auditing. Giving them the same power as a working agent is a mismatch that eventually causes a mistake. The Viewer role closes that gap.

What a Viewer can and cannot do

A Viewer sees a real, live view of the work, scoped to only what you assign.

  • Can see the sites assigned to them, the visitors on those sites, and the unified inbox for those conversations.
  • Can follow conversations as they happen, in real time, the same way an agent sees them.
  • Cannot reply to a visitor, send a message, or take a call.
  • Cannot edit a visitor record, a lead, a note, or any customer data.
  • Cannot change settings, the AI knowledge, team members, or any workspace configuration.
  • Cannot delete anything.

In short, a Viewer reads. Every path that would write something is closed to them.

Why the block lives in two places

A read only role is only as good as its weakest enforcement point. Blocking a button in the interface is not enough, because the interface is not the only way to reach your data. ZenTalk enforces the Viewer restriction at both layers a request can travel through.

  1. The API. Every write request from a Viewer is rejected at the server before it can touch your database, through a single global check rather than a scatter of per endpoint rules that can be missed.
  2. The realtime layer. The live socket that carries chat and presence also refuses write actions from a Viewer, so a Viewer cannot send a message even by going around the normal interface.

This is the difference between a role that looks read only and one that truly is. You can read more about how we think about access and data safety on our security page.

Who the Viewer role is for

Onboarding new agents safely

Put a trainee in as a Viewer on their first days. They watch real conversations, learn your tone, and see how your best agents handle a tricky visitor, all with zero chance of sending something they should not. When they are ready, you promote them to a full agent. It is the calmest way to bring someone up to speed.

Giving a client visibility

Some clients want to see how their account or their leads are being handled without being pulled into the day to day. Assign them Viewer access to just their own sites and they get a live, honest window, and nothing they can break.

Letting a compliance or QA reviewer audit

Auditors and quality reviewers need to inspect what was said and what was done. A Viewer can read the conversations and records that back up your reporting and insights without any ability to alter the very evidence they are reviewing, which is exactly what a clean audit requires.

Why least privilege matters

Least privilege is a simple, old idea: give each person the smallest amount of access they need to do their job, and no more. It is not about distrust. It is about removing the chance for an honest mistake to become a real problem.

  • A trainee cannot accidentally message a live customer.
  • A client cannot change data that belongs to your team.
  • An auditor cannot alter the record they are auditing.
  • Every extra person with write access is one more way a mistake can happen. Viewers add zero.

The Viewer role sits alongside the rest of how ZenTalk keeps day to day work tidy and accountable in your operations tools, where every action lands in one shared record and one audit log.

Setting it up

Add the person to your team, choose the Viewer role, and assign the specific sites you want them to see. That is the whole setup. They log in, they see exactly what you gave them, and every write path stays closed. When their reason for viewing ends, remove the access in one step.

If you only remember one thing

Visibility and control are two different permissions, and they should be handed out separately. The Viewer role lets you give the right people a real look inside, managers, trainees, clients, and auditors, without handing anyone the power to change something they should not. It is available now, with a one week free trial when you ask.

Common questions

What can a Viewer see in ZenTalk?

A Viewer can see the sites you assign to them, the visitors on those sites, and the unified inbox for those conversations, in real time. They see the work the same way an agent does, but only for what you have assigned.

Can a Viewer reply to customers or edit anything?

No. Viewers are blocked from every write action. They cannot reply to a visitor, take a call, edit a record, change settings, or delete anything. The block is enforced at both the API and the realtime layer, so there is no way around it.

Who should I give the Viewer role to?

It is built for people who need to see the work without touching it. Common cases are onboarding a new agent safely, giving a client visibility into their own account, and letting a compliance or QA reviewer audit conversations and records.

Ready to try it?

See the AI agent work on your own site.

Start your one week free trial, and we will walk your workspace through setup personally.

One week free. Cancel anytime. No long-term contract.