GenEmails application roles
GenEmails reads the user's Genesys Cloud role names at login and chooses the most restrictive assigned GenEmails role in this order: APP_GEM_AGENT, APP_GEM_SUPERVISOR, APP_GEM_ADMIN. A user without one of these roles is denied GenEmails access.
| Role | Typical role scope | Typical Genesys Cloud permissions |
|---|---|---|
| APP_GEM_AGENT | Operational mailbox handling with limited actions. Common defaults: Current Emails, attachments, Assign to Me, Move to SPAM, Disconnect, and Send to Review Queue where configured. | Read conversations, queues, and mailbox data needed for assigned work; conversation assignment to self if enabled; queue membership visibility. |
| APP_GEM_SUPERVISOR | Operational triage across Current Emails, Review Queue, and SPAM Queue. Common defaults include assignment, skill routing, queue transfer, priority changes, and SPAM table write but not SPAM table delete. | Queue and conversation read access; conversation assign, transfer, and replace queue; routing skill read; disconnect if supervisors can close interactions. |
| APP_GEM_ADMIN | Full GenEmails administration: Admin Console, mappings, backups, access control, SPAM table write or delete, and all operational actions. | Genesys administrative read permissions for queues, divisions, email domains, routes, data tables, and the corresponding write permissions. |
Important distinction: APP_GEM roles are application-level gates only. They do not elevate Genesys privileges. GenEmails uses the signed-in user's OAuth token for user-initiated Genesys operations, so Genesys can still deny an action even when Access Control allows it.