---
title: "Callroute Administrators"
canonical: "https://help.callroute.com/space/CKB/783482881/Callroute%20Administrators"
format: markdown
---
Callroute utilises Role-Based Access Controls (RBAC) to enable the delegation of administrative tasks among multiple administrators. Our product offers a range of pre-defined user roles to effectively manage your Callroute service. Customers also have the flexibility to create custom roles tailored to their specific needs, empowering them to define granular permissions.

## Best practice for assigning RBAC

When defining Role-Based Access Controls it is important to consider the task responsibilities of your Callroute administrators, adhere to the principle of least privilege, regularly review and update roles, and ensure effective documentation and communication of role definitions.

To begin, it is important to consider the appropriate individuals who should have the ability to perform the following tasks:

- Deleting a service connection (eg. Microsoft Teams) and enabling the automatic removal of all voice policies from the tenant.
- Accessing and managing call recordings for the entire tenant, including the ability to listen to and download them.
- Modifying privileges for admin user roles, granting or revoking specific permissions.
- Viewing or modifying the routing destinations for number assignments.

## Pre-defined roles

For streamlined setup, Callroute offers a range of pre-defined roles with predefined permissions. This enables users to quickly assign appropriate access levels without the need for extensive customization.

![image](media://3c38a150-5fa2-4034-b70a-f2336afb1316)

Below is a matrix displaying an overview of available roles and their corresponding permissions for quick reference.

![image](media://8a88abb1-ff9f-4eb2-8c67-4d360cdcfceb)

> ℹ️ Partner Super User will also apply these role permissions to all associated sub-customers.