Leexi
Roles and security

Access rule types

The three types of access rules, their fields, their exceptions and how they combine with roles and call sharing.
Definition: An access rule opens visibility on the calls of a set of people (Data of) to a set of recipients (Visible by). Rules are managed under Settings > Governance > Access rules, a page restricted to people allowed to manage access rules (System admin and Super admin). The page opens from the AI Meeting plan; fine-grained rules and exceptions require the Governance add-on.

Settings at the top of the page

Two accordions precede the list of rules. The same switches also appear on the Permissions page.

Analytics Access rules

SettingOptionsDefaultRequiresEffect
Allow Super Administrators to access all analytics without visibility restrictionsYes / NoNoRestricted to people allowed to change company settingsSuper admins see the analytics of the whole company, even on calls the access rules do not open to them.
Allow Company Managers to access all analytics without visibility restrictionsYes / NoNoRestricted to people allowed to change company settingsCompany managers see the analytics of the whole company, even on calls the access rules do not open to them.
Allow Team Managers to access their teams' analytics without visibility restrictionsYes / NoNoRestricted to people allowed to change company settingsTeam managers see their team's analytics, even on calls the access rules do not open to them.

These switches only affect analytics: they do not open the reading of the calls themselves.

Leexi Access

SettingOptionsDefaultRequiresEffect
Allow access to Leexi support for troubleshootingYes / NoYesRestricted to Super adminsWhen disabled, Leexi support can no longer log in to your workspace nor export your calls to diagnose an incident. Support requests take longer.

Fixed rule

A banner recalls the rule that applies before any access rule: a user sees the calls they took part in, and the calls for which they have access to every attendee. An access rule never removes this visibility; it adds to it.

The three rule types

Each type has its own section, its own Add button and its own list. The user rules section is always shown; the API key and webhook sections only appear if the company has at least one API key or webhook. A rule never mixes types: its recipients are either users, teams or the company, or API keys, or webhooks. An API key or webhook attached to a user inherits that user's access and needs no rule; without an attached user, only its access rules decide what it sees, and without a rule it sees nothing.

TypeSection titlePossible recipients (Visible by)What the rule opens
User access rulesUser access rulesEntire company, teams, usersViewing calls in the app, the library, analytics and scorecards.
API key access rulesAPI key access rulesOne or more API keysThe calls external tools can read through the public API with that key.
Webhook access rulesWebhook access rulesOne or more webhooksThe calls whose events are sent to the webhook's destination.

Fields of a rule

The fields are the same for the three types, except for the Visible by block.

FieldOptionsDefaultRequiresEffect
Data of: Entire companyYes / NoNoAI Meeting planMakes the calls of every user accessible. When enabled, the other fields of the block are greyed out.
Data of: TeamsOne or more teams—Governance add-onMakes the calls of these teams' members accessible.
Data of: UsersOne or more users, active or inactive—Governance add-onMakes these people's calls accessible.
Data of: Conversation typeOne or more conversation types, active or inactive—Governance add-onLimits the rule to calls of these types. Empty, the rule covers every type. An inactive type stays selectable because the rule keeps applying to its past calls.
Except: UsersOne or more users—Governance add-onRemoves these people from the Data of scope without creating a second rule. A user already chosen in Data of cannot be excluded, unless Entire company is enabled.
Except: Conversation typeOne or more conversation types—Governance add-onRemoves these types from the rule's scope. Incompatible with a type already included, unless Entire company is enabled.
Visible by: Entire companyYes / No (user rules only)NoAI Meeting planGrants access to every user. When enabled, the Teams and Users fields are greyed out.
Visible by: TeamsOne or more teams (user rules only)—Governance add-onGrants access to these teams' members.
Visible by: UsersOne or more users (user rules only)—Governance add-onGrants access to these people.
Visible by: API keyOne or more API keys (API key rules only)—AI Meeting planGrants access to these keys.
Visible by: WebhookOne or more webhooks (webhook rules only)—AI Meeting planGrants access to these webhooks.
ActiveYes / NoYes—When disabled, the rule is kept but no longer opens any access. Disabling a rule stays possible even after losing the plan or add-on that allowed it.

A rule must contain Entire company, at least one team or at least one user in Data of (a meeting type alone is not enough) and at least one recipient in Visible by, otherwise saving is refused.

What is basic and what requires Governance

Rule formRequires
Data of: Entire company, Visible by: Entire company, with no exception or conversation typeAI Meeting plan
Data of: Entire company, Visible by: one or more API keys or webhooks, with no exception or typeAI Meeting plan
Any rule targeting teams, users or conversation types, or containing an exceptionGovernance add-on

Without Governance, the Teams, Users and Conversation type fields and the Except block do not appear in the form. When the add-on is removed, existing advanced rules stay in place: they can be disabled but no longer edited.

Combination with roles and call sharing

  • A role decides what a user can do; an access rule decides which calls they see. Without the capability to view calls (see Roles), no rule opens anything.
  • Rules add up: a user sees a call as soon as they took part in it or as soon as an active rule gives them access to every attendee of the call. A call between two people is only visible if the user has access to both people's calls.
  • On a call, the Sharing & Access tab shows the users who access it through the rules. Enabling custom access replaces the rules for that call: only manually added users see it. Changing this access requires the capability to edit a call's access, within the role's scope (own calls, team calls or all calls).
  • API key and webhook rules are computed on every request and every event sent: changing a rule immediately changes what the external tool receives. A key or webhook without an attached user also sees custom-access calls, as long as its rules cover every attendee.

Previous and next pages

Copyright © 2026 Leexi