# Inbox

Let a business's staff answer WhatsApp in PaalChat's inbox, signed in from your product - no second password.

> **In a nutshell:** Your product signs a logged-in staff member in with POST .../inbox/sign-in and redirects them to the one-time url it returns (5 minutes, one use). PaalChat shows that business's conversations only; roles admin, agent and viewer decide what they may do. Remove access with DELETE .../inbox/members/{id} when staff leave.

PaalChat has its own inbox where a business's staff read and answer WhatsApp: assign
conversations, reply inside the 24-hour window, send approved templates outside it, add
internal notes and tags, and change status and priority. Your product does not need to build
one. The inbox is enabled per business by PaalTech.

The inbox works on phones and desktops, and follows each person's light or dark setting
(or their device's), switchable in its header.

## Signing staff in

PaalChat never holds staff passwords: your product, where the staff member is already
signed in, vouches for them.

1. When the staff member clicks "WhatsApp inbox" in your product, call
   [Sign staff in to the inbox](/docs/api/inbox-sign-in) with who they are and their role:

   ```json
   {"staff": {"external_id": "teacher-12", "name": "Kwame Owusu", "email": "owusu@presec.edu.gh", "role": "agent"}}
   ```

2. Redirect their browser to `data.url`. It works **once**, within **5 minutes** - request
   a new one every time, from your server, never ahead of time.
3. They land in the inbox of that business only. Add `conversation_id` to open a
   conversation directly (for example from a notification).

The name and role you send replace the stored ones each time, so a promotion takes effect
on the next sign-in.

| Role | Can |
|---|---|
| `viewer` | Read conversations, messages, notes and tags |
| `agent` | Also reply, send templates, add notes, change status, priority and tags, take or release a conversation |
| `admin` | Also assign conversations to anyone |

## When staff leave

Call [Remove inbox access](/docs/api/disable-inbox-member) with their `external_id`. An open
inbox signs out on its next click, and their conversations become unassigned. Signing them in
again restores access. [List inbox members](/docs/api/list-inbox-members) shows who has access.

## Assigning from your product

[Update conversation](/docs/api/update-conversation) takes `assignee`: an inbox member's
`external_id` (sign them in once first), or `null`. Conversations carry their `assignee`, and
changes arrive as `conversation.updated` with `change: assigned` or `unassigned`.

## What PaalTech sees

PaalTech operators see conversation counts and statuses for support - never message text.
Message content is for the business's own staff, in the inbox or through your product.
