Skip to content

Security & API

Control who accesses what with granular permissions, user profiles, teams, and API keys — with best practices for organization isolation and GDPR/LGPD compliance.

What it's for

  • Owners and administrators configuring the organization, teams, and integrations
  • Managers organizing support rotation and supervision by team
  • Agents with limited access (hidden data, restricted filters)
  • Developers integrating systems via API and webhooks

What you can do

  • Configure organization: name, logo, timezone, language, and support preferences
  • Define granular profiles: owner, admin, manager, agent, agent_limited, financial, sales, medical_*
  • Hide contact data from agents and restrict CRM visibility by team (GDPR/LGPD)
  • Manage teams with leaders, automatic flow on transfer, and smart rotation
  • Configure rotation with triggers, auto-answer/reserve modes, fallback, schedules, and on-call
  • Connect integrations: OpenAI, DeepSeek, ElevenLabs, Minimax, Firecrawl, and S3
  • Generate API keys for integration with the Interflow API
  • Control channel visibility and pause flows when taking over support manually

How it connects

Guides

Documentation constantly being updated