Request for Role-Based Restrictions on Chat Reports for Team Leaders

Bruce Smith

Premier Customer
Basic Certified
Joined
Mar 28, 2020
Messages
75
Reaction score
18
We are experiencing an issue with the current permissions model for Team Leaders in 3CX. At present, Team Leaders have access to chat reports, which is creating a significant governance and HR concern.

Some Team Leaders are using chat report access to monitor conversations between other staff members, and in several cases this has led to unnecessary or inappropriate HR complaints. This behaviour is outside the intended operational scope of their role and is causing internal friction.

To maintain them as Team Leaders while ensuring proper data governance, we need one of the following capabilities:
  • The ability to disable access to chat reports specifically for the Team Leader role
    or
  • The ability to fully restrict access to all reports for selected Team Leaders while retaining their other leadership permissions
This would allow us to preserve the operational benefits of the Team Leader role without exposing sensitive communication data or enabling misuse of reporting tools.

Could you advise whether 3CX currently supports granular report‑level permissions, or if this can be added to the roadmap? Any guidance or recommended configuration changes would be appreciated.
 
Hi Bruce

Are you able to describe an absolutely minimal setup that would allow me to replicate this in a test environment?

So, creation of 2 users that would be in their own department, one with a role that gets the reports and one with a role that does not get the reports, creation of the dedicated department for these 2 users, creation of the dedicated queue for these 2 users, any maybe a screen grab showing the issue?
 
Hi,

The setup is actually extremely simple — this isn’t a complex environment‑specific issue, it’s a permissions‑scope issue.

All that’s required to reproduce it is:
  • Two standard call‑centre users who can message each other via 3CX internal chat
  • One manager with the Supervisor role assigned
When User A sends an internal chat message to User B, the Supervisor can open Chat Reports and read their conversation in full. These are private, internal staff messages, not queue‑related interactions, yet the Supervisor role has unrestricted visibility.

This level of access should only be available to the System Owner / Administrator, not to Supervisors or Team Leaders, Managers. The concern is that this allows supervisors to monitor personal internal chats and use them for HR complaints, which is not appropriate for their role.

There looking at chats that go back to 2024, i should not have to delete logs to stop this.

The issue isn’t tied to departments, queues, or any special configuration — it’s simply that the Supervisor role currently has access to chat reports that expose private staff conversations.
 
As you have probably already realised, the roles are pre-defined; you can get some insight here: https://www.3cx.com/docs/manual/access-roles/

The ONE way I can think to address your issue to some extent is to select a role that does NOT provide reporting access, and use scheduled reports as the main reporting vehicle - but I suppose the old maxim is true: YMMV.
 
That leaves only user or reception, just not good enough.
 

Members Online Now

Forum statistics

Threads
111,831
Messages
589,277
Members
164,660
Latest member
RJenkinsROCK