Per-employee permissions: how to let telecallers work without letting the lead list walk out
Export, transfer, delete, edit statuses, see other people's leads: each should be a switch per employee. What to lock by default, what to open, and how permission-gated deletes protect a year of history.
Team & reports 24 July 2026· 2 min read· By Sensy Talk
Your lead list is the most valuable file in the company and the easiest to lose. Not to hackers: to a caller who exports it before joining a competitor, or a well-meaning manager who deletes the wrong segment. Permissions are how you let people work without handing them the keys.
The default posture
Start closed, open by need:
| Capability | Caller | Manager | Owner |
|---|---|---|---|
| See own assigned leads | Yes | Yes | Yes |
| See team leads | No | Own team | All |
| Add leads and remarks | Yes | Yes | Yes |
| Edit statuses and custom fields | No | Yes | Yes |
| Transfer leads | No | Yes | Yes |
| Export | No | Maybe | Yes |
| Delete | No | No | Yes |
| Change lead sources and rotations | No | Yes | Yes |
| Web dashboard | No | Team | All |
Every row is a switch per employee, so a trusted senior caller can get Transfer without getting Export.
Why deletes go through the server
If a phone could delete locally and that deletion synced everywhere, one angry afternoon could erase a year. In SensyConnect, deleting a lead, remark, reminder or client is a permission, and the delete is sent to the server, retried until confirmed, and logged. No permission, no delete button. Owner-level users can still clean up; nobody can do it by accident.
Exports are the sensitive one
Exporting a filtered list to Excel is a legitimate owner task and the single biggest leak risk. Keep it off for callers, on for the owner, and give it to a manager only with a reason. Because it is a switch, you can flip it on for the afternoon and off again.
Departures without drama
When someone leaves: deactivate the user, reassign their queue (history intact), and their phone loses access on the next sync. Nothing needs to be “collected” from the device.
Field-level protection
Statuses, custom fields and lead forms are company vocabulary; if any caller can rename “Interested” to “Hot”, reports break. Keep status and field editing with managers and the owner.
Transparency, not surveillance
Permissions are not about distrust; they are about clarity. Callers know they own their queue and are measured on it; managers know they can move work; the owner knows the data cannot leave or vanish. Say that out loud when you set it up.
Permissions, gated deletes and reassignment are all part of the SensyConnect plan; see team features or start the free trial and set up your first two roles.
Frequently asked
Can a caller export the lead list?
Only if you turn on Export for them. By default they cannot, and the app's exports are gated by that permission.
What happens when someone leaves?
Deactivate the user; their leads, remarks and chats stay in the account and can be reassigned. Their phone loses access at the next sync.
Are deletes reversible?
Deletes are permission-gated and logged. Only users with the delete permission can remove records, and the delete goes through the server, so nothing disappears silently from one phone.
See it on your own leads
Free 3-day trial, every feature, no card. Or a 15-minute demo on WhatsApp.
More on team & reports
The assigned-leads queue: how a manager hands out work and a caller works it, without a spreadsheet
Assignment on the web, a queue on the phone, an auto dialer that runs it, and outcomes that report back. How assigned leads work end to end, including transfers, call-due dates and completed-vs-pending views.
The owner's dashboard: how to see your telecalling team's day without asking anyone
Evening reports are written by the people being reported on. Here is what a live team dashboard should show (calls, outcomes, follow-ups, speed to lead, per person and per source) and how it changes the conversation with the team.