Security: Role-based access, not a shared login for the entire company

In volbor, customer conversations are visible only to team members granted specific workspace roles. Using a shared team password or forwarding chat excerpts to personal messaging apps undermines this rule: the platform cannot audit who accessed customer data. This page outlines how access governance works. It does not constitute a compliance certificate, third-party audit, or an uptime percentage guarantee.

This document does not substitute contractual terms. For a technical description of how data is processed outside contract terms, review our Privacy Policy.

Get startedLearn more
  1. 01
    Single login per department

    impossible to audit who replied or exported history. Offboarding employees does not revoke access until everyone updates the password.

  2. 02
    Unrestricted access across teams “just in case”

    sales reps browse support queues and vice versa, creating confusion around commitments made to customers.

  3. 03
    API keys shared in chat

    integrations retain workspace access long after a team member leaves the company.

  4. 04
    Forwarding to personal chats

    conversation excerpts leak into personal messaging apps, bypassing workspace access controls entirely.

The hidden risks of shared workspace access

  1. 01

    Single login per department

    impossible to audit who replied or exported history. Offboarding employees does not revoke access until everyone updates the password.

  2. 02

    Unrestricted access across teams “just in case”

    sales reps browse support queues and vice versa, creating confusion around commitments made to customers.

  3. 03

    API keys shared in chat

    integrations retain workspace access long after a team member leaves the company.

  4. 04

    Forwarding to personal chats

    conversation excerpts leak into personal messaging apps, bypassing workspace access controls entirely.

Core access control practices

  1. 01

    1. Assign individual user accounts per team member

    Never share accounts across shifts or branch locations. Inviting and deactivating users aligns directly with individual employee offboarding. Explore roles and channel boundaries in Access Permissions & ACL.

  2. 02

    2. Restrict channel access strictly to assigned agents

    Support agents shouldn't see confidential sales deals, and vice versa. Custom views and Smart Folders help keep feeds tidy, but true data isolation begins with workspace roles, not UI filters.

  3. 03

    3. Separate integration credentials from employee logins

    Webhooks and APIs must use dedicated API secrets. When an employee leaves, their user login is revoked immediately, and shared API keys should be rotated independently.

  4. 04

    4. Never forward conversation excerpts to personal chats

    Collaborate using internal notes directly inside the conversation thread. Copying snippets into personal messaging apps creates an unmonitored perimeter that access controls cannot protect.

What this page does not cover

This page does not promise isolated infrastructure clusters, guaranteed uptime percentages, or compliance certifications not explicitly specified in your enterprise agreement. If a setting is not available in the dashboard, this guide does not create it. Multi-team deployments are detailed under Enterprise Teams without unverified claims.

Frequently Asked Questions

Is a strong password enough for a shared account?

No. A shared account cannot identify which agent viewed or handled a conversation. Strong passwords complicate unauthorized logins, but cannot establish individual accountability.

Does volbor view our customer conversations?

Conversation history is stored so your support and sales shifts can reply and maintain context. Which internal team members see each message is determined strictly by your workspace roles. This page does not replace your company's internal data handling policies.

Can we grant temporary access to an external contractor?

Yes. Invite them as an individual user with a restricted role and set a clear offboarding date. Never share existing admin or agent credentials.

What should we do if an API key is exposed in chat?

Regenerate the key immediately and treat the compromised secret as invalid. Changing an employee's password does not automatically revoke API keys.

Is this compliant with specific regional privacy laws?

We align our data governance with standard international data protection frameworks such as GDPR. We do not make jurisdiction-specific legal guarantees here, and this page does not serve as legal advice.

Helpful Resources & Related Solutions

  • Access PermissionsWhy it matters: Assign granular roles to specific queues instead of company-wide access.
    Without it: Security policies remain theoretical while your workspace remains open to every invited member.
  • Webhooks and APIWhy it matters: Isolate programmatic integrations with dedicated API secrets.
    Without it: System integrations get entangled with personal employee logins.
  • Unified InboxWhy it matters: Respond within role boundaries rather than forwarding chats to personal apps.
    Without it: Conversation data leaks beyond your governed workspace.
  • Enterprise TeamsWhy it matters: When managing multiple teams and basic agent roles are no longer sufficient.
    Without it: All departments remain grouped in a single noisy inbox.
  • Privacy PolicyWhy it matters: Review product data processing specifications, keeping in mind they are not contractual terms.
    Without it: Access rules get configured without understanding data retention practices.
  • For DevelopersWhy it matters: Restrict integration environments to technical leads who hold API secrets.
    Without it: Secret credentials end up in general launch chat rooms.