Inviting users
Invite by email from Organization. The invitee sets their own password and joins your workspace — never share a login.Roles
Recepta.ai ships with standard roles covering the common cases, and supports custom roles when those don’t fit.Standard roles
Owner and administrative roles for people who configure the system, plus operational roles for people who work calls and bookings day to day.
Custom roles
Build a role from individual permissions when the standard set is too broad or too narrow for someone’s job.
What to be careful with
Billing
Billing
Keep billing access to the people who should see and change what you pay. It’s separate from configuration access for good reason.
Recordings and transcripts
Recordings and transcripts
Call content contains customer personal data. Grant it to people who need it for QA and support, not by default. Transcript and recording access can be granted separately — including at the API key level.
Integrations
Integrations
Anyone who can disconnect an integration can stop bookings reaching your CRM. Restrict it.
Contact deletion
Contact deletion
Deletion is not reversible. Few people need it.
When someone leaves
1
Remove their user
Do it the same day. Their access ends immediately.
2
Check integrations they authorized
An OAuth connection authorized with their account can stop working when their access at the provider is revoked. Reconnect anything they owned under an account that will persist.
3
Rotate any API keys they created
Keys survive the user who made them. See Authentication.
Running multiple locations? Access can be scoped so branch staff see their own location’s calls and bookings without seeing the whole business.
