Skip to content

Workspace, members and security

Everything that applies to your whole workspace: who has access and with which role, API keys, usage, support access, the audit log and data retention.

Updated

On this page

Members and roles

#
Roles
RoleCan do
AgentThe live support inbox only
MemberView bots, add and edit knowledge, read conversations and analytics
AdminEverything a member can, plus bot settings, provider keys, API keys, members, tools, live support settings, usage and the audit log
OwnerEverything, plus deleting the workspace, managing owners and support access
  • Invite by email from Members. Invitations expire after 7 days; pending invitations count towards your plan's member limit.
  • Turn on Live support for any member, admin or owner to give them the inbox as well.
  • Only an owner can invite, promote, demote or remove an owner, and a workspace always keeps at least one owner.
  • To hand over ownership, make the new person an owner, then change your own role or leave.
  • Removing someone takes effect immediately.

API keys

#

API keys let your own servers use the Kothadesk API, for example to add knowledge or export conversations. Create them under API keys.

  • Choose a name, Live or Test, an expiry (never, 30 days, 90 days or 1 year) and access: full access, or restricted scopes (bots, knowledge and conversations read or write, analytics read).
  • The full key is shown once. Store it in your secret manager.
  • Keys can never manage members, other keys, provider keys, tools, live support, usage or the audit log.
  • Roll a key to get a new one with the same settings. The old key keeps working for a grace period you choose: immediately, 1 hour, 24 hours (default) or 7 days.
  • Revoke a key and requests using it fail immediately.

Watch out: API keys belong on servers only. For the website widget no key is needed; for mobile apps use the publishable key from the Install tab.

Usage and limits

#

Settings, Usage shows your plan, what you have used this month (visitor messages, ingested pages, evaluation runs) and your resources (bots, members, sources, documents, storage, tools). Monthly limits reset on the first day of the month (UTC). A Near a limit badge warns you in time.

Below it, the model usage report shows estimated AI cost, tokens and calls for any range of days, by bot, type and model, with a CSV export. Your provider bills this usage directly; Kothadesk does not charge for it.

Support access

#
Support access policies
PolicyMeaning
Ask me first (default)Kothadesk support needs an owner's approval for each read-only session
AllowedSupport may open a read-only session of up to 4 hours without asking; you can revoke it
DeniedSupport cannot access the workspace

Sessions are read-only, last at most 4 hours, never show secrets and are written to the audit log. Requests you do not answer expire after 24 hours. Only owners can change the policy.

Audit log

#

Security-relevant changes, newest first, kept for 400 days: members and roles, invitations, API keys, provider keys, bots, knowledge, tools, support access and exports. Filter by who did it (a member, an API key, platform support or the system), the action, the resource and dates; open an entry for details or export the log as CSV.

Workspace settings and data

#
  • Workspace name, default language (new bots start with it) and time zone. The URL slug cannot be changed.
  • Keep conversations for 1 to 365 days (default 365). Older conversations are deleted automatically.
  • Export or erase one visitor's data from their conversation, for access and deletion requests.
  • Deleting the workspace (owners only) stops bots and API keys at once and deletes everything permanently after 30 days; an owner can cancel until then.

Worked examples

#

Online shop

A small store team

The owner manages settings, two staff answer chats.

Owner: the founder. Two Agents for the inbox. The Free plan's 3 members covers this team.

Clinic or bookings

Reception and a clinic manager

The manager keeps knowledge up to date; reception handles chats.

Manager: Member with Live support on, so they edit knowledge and also answer chats. Receptionists: Agents. Support access: Ask me first.

Software company

Syncing knowledge from a docs pipeline

Publish new docs to the bot automatically from the build system.

An API key with the knowledge:write scope, expiring in 90 days. Before it expires, roll it with a 24-hour grace period and update the pipeline's secret.

Coaching institute

Counsellors across two centres

Each centre's counsellors see only their chats.

Invite counsellors as Agents and put them in teams per centre (see the Live support guide). Keep conversations for 180 days to match the institute's privacy notice.