Roles & Permissions

GenEmails application roles

GenEmails reads the user's Genesys Cloud role names at login and chooses the most restrictive assigned GenEmails role in this order: APP_GEM_AGENT, APP_GEM_SUPERVISOR, APP_GEM_ADMIN. A user without one of these roles is denied GenEmails access.

RoleTypical role scopeTypical Genesys Cloud permissions
APP_GEM_AGENTOperational mailbox handling with limited actions. Common defaults: Current Emails, attachments, Assign to Me, Move to SPAM, Disconnect, and Send to Review Queue where configured.Read conversations, queues, and mailbox data needed for assigned work; conversation assignment to self if enabled; queue membership visibility.
APP_GEM_SUPERVISOROperational triage across Current Emails, Review Queue, and SPAM Queue. Common defaults include assignment, skill routing, queue transfer, priority changes, and SPAM table write but not SPAM table delete.Queue and conversation read access; conversation assign, transfer, and replace queue; routing skill read; disconnect if supervisors can close interactions.
APP_GEM_ADMINFull GenEmails administration: Admin Console, mappings, backups, access control, SPAM table write or delete, and all operational actions.Genesys administrative read permissions for queues, divisions, email domains, routes, data tables, and the corresponding write permissions.

Important distinction: APP_GEM roles are application-level gates only. They do not elevate Genesys privileges. GenEmails uses the signed-in user's OAuth token for user-initiated Genesys operations, so Genesys can still deny an action even when Access Control allows it.