3CX User Permissions in CallCenterDashboards: Who Can See What?
An agent needs to understand their own performance. A supervisor needs to understand their team's. Neither requirement means everyone should see every call, caller number or agent statistic across the business.
CallCenterDashboards (CCD) now uses the effective visibility permissions received from 3CX to determine what extension-linked users can see in the web portal. Agents can sign in to review their own live call notifications, dashboards and historical reporting, while additional team and queue visibility depends on their permissions.
The important distinction is authorized data, not automatically company-wide data. This guide explains the 3CX V20 permission model, CCD's implementation, and how to check an account when its view is broader or narrower than expected. It covers portal data access, not general PBX hardening or every native 3CX feature.
The takeaway: An agent account can provide a personal view without being a management account. But "agent" does not automatically mean "own data only": department rights, published presence and queue-management assignments can expand what that person sees.
How 3CX V20 user permissions work
Departments define scope; View settings refine it
A department organizes users and provides a scope for delegated permissions. In the 3CX Admin Console, department membership and options are managed under Admin > Departments.
The Publish department information to all extensions option controls whether department members are visible outside their department. Separately, a user's View settings can grant or remove access involving particular departments, including departments that user does not belong to. Being visible is not the same as making all call information available. See 3CX's department and call-view guidance.
Presence, call details and call control are different
3CX distinguishes department-level roles from system-wide roles. A User has basic rights; a Supervisor has reporting and queue-oversight capabilities; Managers and Owners have additional authority. System Administrator and System Owner are also different: 3CX specifically restricts the System Administrator's access to recordings, reports and call monitoring.
A role name alone is therefore not a complete access test. Check the applicable scope and effective permissions, using 3CX's User Access Roles Explained. Also distinguish the Supervisor role from being assigned to supervise a particular queue.
Presence, call details and call control are different
These three settings are especially important:
|
3CX setting
|
What it controls
|
|
See Presence
|
Whether the viewer can see another user's availability or status within the permitted scope.
|
|
See Calls
|
Whether the viewer can see another user's active call information within the permitted scope.
|
|
Show My Calls
|
Whether the person being viewed makes their call information available to authorized colleagues.
|
For example, seeing that a colleague is busy does not necessarily grant access to the number they are calling. Call Operations, User Operations, and monitoring or recording rights are separate controls; permission to view a call is not permission to transfer it, listen to it or play a recording.
The official 3CX guide to call and presence permissions explains the controls under Admin > Users > select a user > View.
Queue membership is not the same as queue login
Queue membership identifies an agent assigned to handle that queue's calls. Queue login status determines whether the agent is currently participating in call distribution. A person can belong to several queues and be logged out of some of them.
Assigned queue managers can also log agents in or out on their behalf. These operational states should not be confused with a complete data-access policy. Read Managing Agents' Status in Queues for the distinction.
How CCD applies 3CX permissions in the web portal
The portal starts with the user's linked extension
For an extension-linked CCD account, the portal identifies that extension and evaluates its effective group rights and queue relationships received from 3CX. The group-based member rights supplied by 3CX reflect its role and View configuration. CCD uses those rights rather than assigning access solely from a label such as User or Manager.
The user's own extension is always included in their visibility scope. Access to other extensions is then evaluated separately. That is what makes personal agent dashboards and reporting possible without automatically opening company-wide call data.
Important account distinction: A CCD account with no associated extension has unrestricted visibility within its company, including historical queues and hidden extensions. It is not a restricted agent account. Use correctly linked individual accounts for agents; do not share an unrestricted administrative login.
An extension-linked account does not receive a separate CCD bypass just because its 3CX role is System Owner. Its effective group rights still determine its scope.
Both sides of a visibility relationship matter
For ordinary group-based visibility, CCD checks the viewer's rights and the information published by the other extension in the same effective group context. Presence requires permission to see group members and the other extension's published presence. Call visibility additionally requires permission to see group calls and the other extension's published calls.
This explains why a user may see a colleague's status without seeing their calls. Publishing a department's presence outside its own group also does not, by itself, grant those outside viewers access to its calls. Queue supervision is a separate access path, described below.
Live notifications and historical calls use permission checks
CCD filters the live event payload for the signed-in user, rather than merely hiding unwanted information on a page. Call dashboards, statistics, drill-downs and reports also apply visibility checks in the data layer.
Calls can contain multiple legs, such as a transfer from one extension to another. A call can qualify for visibility when a leg involves the viewer's own extension or another extension whose calls they may see. Where the other party is an extension outside that visibility scope, its details are redacted. A visible call therefore does not automatically make every internal participant's identity visible.
This is why "my calls" should be understood as permitted call activity, not a promise that every record contains only one participant.
Queue access has its own rules in CCD
For extension-linked accounts, CCD exposes a queue when the extension is a member or an assigned manager of that queue. Department membership alone does not grant CCD queue visibility.
Seeing the queue does not automatically grant unrestricted access to all its calls or statistics. For a visible queue, a call can qualify when its called extension is visible to the viewer, the viewer manages the queue, the viewer is the called party, or no called extension is assigned. The specific exception is an unanswered queue call with no agent polling: only queue managers can see that call.
Full queue statistics are gated by managed-queue access. The queue-statistics logic can also retain personally answered calls from a queue the viewer is not in, without granting general access to that queue.
Queue-manager access is broader than agent access. In CCD, an assigned queue manager gains presence and call visibility for that queue's agents, including agents otherwise hidden by ordinary group rules. This is extension-level call visibility, not a guarantee that the manager sees only calls routed through that queue. Review the assignment accordingly; it is not merely a notification preference.
For the underlying 3CX configuration, Call Queues & Ring Groups documents queue users and the supervisor assignments under the queue's Notifications tab.
Reports follow CCD's permitted call scope
CCD's call statistics and reports use call visibility, not presence visibility alone. Its consistency rule is that the same KPI should reconcile between a dashboard, its details and the corresponding report for the same viewer, metric, filters and data period.
This does not mean every CCD report copies the access rules of the native 3CX Reports menu. 3CX's Call Reporting guide limits that native menu to specified management roles. CCD provides its own reporting experience, using its implemented visibility rules, so an agent can have scoped CCD reporting without being given a native 3CX management role.
Permission changes need to reach both data paths
CCD receives permission updates for its live view and maintains a separate synchronized reporting copy. That reporting copy is updated every few minutes, so a saved 3CX change should not be treated as instantly applied everywhere. Verify both paths after synchronization; refreshing a browser is not proof that permission data has refreshed.
If the permission cache cannot be loaded for a restricted view, CCD is designed to show no data rather than grant unrestricted access. This safeguard is not a promise of immediate revocation during a synchronization interruption, and it does not change the unrestricted-account behavior described above.
An agent and a supervisor: two appropriate views
Consider two illustrative accounts, each linked to its own extension.
Sarah, an agent: Sarah has no permission to see colleagues' calls and no queue-manager assignment. Her personal call dashboards, historical call data and related live call notifications are scoped accordingly. She can review her own activity without receiving a company-wide call history. Published colleague presence and permitted queue-level events are separate from that personal call scope.
David, an assigned queue manager: David can oversee his managed queue and receives the associated agent visibility. His results can legitimately be broader than Sarah's, even when both open the same dashboard. Because the manager relationship expands access, it should be assigned only where that oversight is appropriate.
The benefit is practical: agents gain self-service insight into their work, while supervisors retain the wider operational view they need. Different totals between these two accounts are not, by themselves, evidence of missing data.
How to verify 3CX and CCD access
Use a real restricted test account, not an administrator's screen, to verify an agent's experience.
1. Confirm the identity. Verify that the CCD account is linked to the intended 3CX extension. Check the corresponding user in Admin > Users; Creating Users Extensions explains the extension, role and department fields. Confirm that the test account is not an unrestricted CCD account.
2. Review the intended scope. Check department membership, publishing and the user's View settings. For another extension's calls, also review that extension's publishing settings. Inspect every applicable relationship, not just the most obvious department.
3. Check each queue assignment. Under Admin > Call Handling, inspect the queue's Users and Notifications tabs. Distinguish membership, supervisor/manager assignment and current login status. Do not add a supervisory assignment simply to make a missing widget appear.
4. Allow synchronization, then test both live and history. Sign in as the affected user. Place an approved test call involving that extension, then a separate call involving only an out-of-scope extension. Check the live notifications, the relevant dashboard and the corresponding completed-call report. The second call should not appear unless another applicable permission or queue rule makes it visible.
5. Compare like with like. Use the same viewer, date range, time zone, filters and metric definition. Compare completed, synchronized data rather than expecting an active-call display to match a historical report immediately. Repeat the test after materially changing departments or queue responsibilities.
Troubleshooting missing or unexpected portal data
A smaller view after a permission update may be intentional filtering. Start with the account and scope before treating it as a collection failure.
|
What you see
|
What to check
|
|
An agent sees much more than expected
|
Confirm the linked extension first. An account without one is unrestricted. Then check additional group rights, published presence and queue-manager assignments.
|
|
A colleague's status appears, but their calls do not
|
Presence and call visibility are separate. Review the viewer's call rights and the other extension's published call information.
|
|
A queue is missing, or its totals are unavailable
|
Check queue membership or management, not only department membership. Queue visibility and full queue-statistics access are separate checks.
|
|
An agent and manager have different totals
|
Compare their permitted scopes before comparing counts. Also align the selected metric, time period, filters and synchronization state.
|
|
A transferred call appears with missing internal-party details
|
The call may involve a visible extension while another participant is outside the viewer's scope. That party's redaction can be expected.
|
|
A restricted account has no data at all
|
Check identity, relevant activity and report filters, then permission synchronization. Failure to load permissions can intentionally produce an empty view.
|
|
A change appears in live data but not reports, or a hidden user appears unexpectedly
|
Check synchronization and the installed build. Verify live and historical behavior separately; escalate a persistent difference rather than widening access to conceal it.
|
Hidden-user caution: Do not rely on hiding an extension alone as a complete access boundary. CCD's hidden-user handling includes exceptions for the extension itself, its supervisors and unrestricted accounts. A hidden extension being absent from a report does not, by itself, confirm that it is absent from live activity. Check both paths. Ask CCD support to confirm behavior for your installed version before relying on this setting for a privacy requirement.
For help, contact your 3CX administrator or CCD support. Include the viewer's extension, affected extension or queue, dashboard/report name, timestamps with time zone, and whether the issue affects live data, historical data or both. Use redacted screenshots; do not send passwords or access tokens.
Two more boundaries worth remembering
Queue logout does not revoke reporting access. Logging out changes call-distribution participation, not the configured membership and rights CCD evaluates. Review the actual assignments when someone's responsibilities change.
This guide is about visibility, not every feature or delivery channel. CCD tracks recording visibility separately from call visibility. Do not infer access to audio, native 3CX call-control actions, APIs, direct database access or externally shared files from what a call dashboard displays. Likewise, a screenshot or downloaded file should only be shared with an appropriate audience.
Official 3CX documentation and reference library
Use these primary sources to verify the underlying 3CX configuration. Their descriptions cover 3CX itself; the CCD-specific behavior is explained in the sections above. Menu labels and available controls can vary with the V20 update and deployment type.
See it with your own 3CX configuration
The most useful test is your own environment. Start with one agent account and one supervisor account, then compare their live activity and reports using the checks above.
New to CallCenterDashboards? Register and download CCD to install it and explore the trial with your own departments, queues and permissions. The aim is not to give everyone the same dashboard data. It is to give each person a useful view that fits their responsibilities.