An older man alone in a hospital waiting room at evening, reading a message on his phone, other patients and a nurse out of focus behind him

Permissions & filtering

Control who sees each conversation

A hundred responders across a dozen countries, and a seeker whose message should be read by three of them. Permissions decide who can see which conversations. Filtering decides what reaches a responder at all.

Permission sets

Each responder sees the conversations they are trained for

Permission sets let you point each responder at what they are good at, trained for, and close to.

  1. A permission set decides what a responder can see. It lists your ministry sources like chat pages, email accounts, phone numbers, and social media accounts. You'll select which of these sources the responders in the set can access. A responder can only see conversations from these sources.

  2. That is as much about focus as it is about access. A responder who is strong on phone calls or live chat can spend their time there, while someone who is great at talking with people on Facebook takes those conversations. Some ministries use sets by region, so seekers are answered by responders who know their area.

  3. A source in a permission set means the responders in that set see everything from it, no matter how it is filtered. A source that reaches a permission set only through a filter means they see just the conversations that filter sends them.

  4. An admin still has to be added to a permission set to see the conversations that arrive on its sources, so full access is not the same as the whole inbox.

Roles

Their role decides their level of access in Echo

Permission sets control the conversations they can see.

Roles: who can see what

Operator

The default account, and what most responders are. They see the conversations that arrive on the sources their permission sets cover, and nothing outside them.

Manager

A leader with responders assigned to them. Everything an operator sees, plus their own team. An operator cannot be given team members at all.

Admin

Full access to everything in Echo. An admin still has to be added to a permission set to see the conversations that arrive on its sources, so full access is not the same as the whole inbox.

Why it matters here

Give each responder only what they need, and take it back quickly

Nobody assumes bad intent. But once a team grows past the point where everyone knows everyone, you need parameters to keep everyone safe. And for a ministry working in a sensitive area, those parameters need to be in place before the first conversation comes in, not after something has gone wrong.

  1. A phone that is lost, seized or searched exposes what that one responder could see, which is why that should be the smallest useful set.

  2. If a phone goes missing, a device is compromised or someone leaves, take them out of their permission sets. The conversations from those sources leave their inbox straight away. Their account stays, so they stay in the reports about each responder.

  3. Deleting the account goes further: it signs them out and stops them signing back in. It also closes their open conversations and takes them off the reports about each responder.

Responders who must stay unidentified. In sensitive areas, who is answering is itself the thing to protect. Security & trust covers that side.

Filtering

Send each conversation to the right people

  1. A rule reads each conversation as it arrives: the words in the message, the channel it came in on, its language and where the seeker is. You write the rules, in the order you want them.

  2. It sends the conversation to the team you name. A group trained to talk with people in crisis gets those conversations straight away, and the last rule always catches the rest, so nothing falls through. When more than one rule matches, every one of them applies, unless you set a rule to stop there.

  3. A filter can tag the conversation and give it a label with its own icon and color, so it stands out in the inbox and the context is there before anyone opens it.

  4. A rule can also mark a conversation as spam. It is closed and kept on record instead of reaching the inbox.

Spam and abuse

What stays out of the inbox

Open channels attract more than seekers. Spam, abuse and coordinated harassment all arrive in the same inbox as the 1am message that matters, and a responder who has to wade through the first is slower to answer the second.

Automatic, on every account

Echo runs the picture check on its own, on every account.

  • Explicit pictures stay covered

    Echo checks pictures as they arrive, using PicPurify, an image moderation service. One it flags as explicit shows up as a note saying so, and a responder only opens it by choosing to.

Set by your ministry

Filters let your ministry set the rest of the rules, and Echo simply follows them. They can be updated and changed as your ministry's needs change.

  • Spam is marked, never deleted

    Inbound email arrives with a spam score from the mail provider. Turn spam filtering on for a group of sources, set how strict the line is, and anything at or above it is marked and closed instead of delivered.

  • Nothing is lost

    Marked spam stays with the client record, and spam is one of the filters in the conversations report. If an admin disagrees with the mark, they can reopen the conversation and it returns to the inbox as though it had just arrived.