From Bright Pattern Documentation

Revision as of 19:04, 5 August 2026 by Wyler.metge (talk | contribs) (Updated via BpClonePage extension. Source page: draft:Security-and-authentication-guide/System-Access-Restrictions)

< Previous | Next >
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to: navigation, search

System Access Restrictions

The System Access Restrictions settings let you limit access to your contact center by client IP address and control whether the system provider can sign in to your tenant. Use them to manage the networks from which users and the applications that call the APIs can connect.


System Access Restrictions


Screen Properties

Limit system access by client IP address

This is the master switch for IP-based access control. When enabled, access is allowed only from the IP address ranges defined below. When disabled, access is not restricted by IP address and the range lists are ignored.

Allow Agent Desktop and Contact Center Administrator applications access from following IP address ranges

This list defines the IP address ranges from which users can access the Agent Desktop and Contact Center Administrator applications. Each range is shown in a table with three columns:

  • Address — the network or IP address of the range.
  • Mask — the subnet mask that, together with the address, defines the range.
  • Description — an optional label that identifies the range, for example the name of an office location.

To add a range, click Add address range. To edit or delete an existing range, use the actions menu () at the end of its row. Adding or editing a range opens the following dialog:


Adding or editing an address range


Enter the following, then click Save (or Cancel to discard your changes):

  • Address (required) — the network or IP address, for example 192.168.1.1.
  • Mask (required) — the subnet mask, for example 255.255.255.0.
  • Description (optional) — a label to help you recognize the range later, for example California Office.

Allow users with "Privileged Access IP Range" privilege from following address ranges

This list defines additional IP address ranges that apply only to users who have the Privileged Access IP Range privilege. These users can connect from these ranges in addition to the ranges defined above. This is useful for administrators who connect from locations outside the general allowlist. Add, edit, and delete ranges the same way as above.

Allow API access from following IP address ranges

This list defines the IP address ranges from which the Bright Pattern Contact Center APIs can be called. When Limit system access by client IP address is enabled, API requests are accepted only from these ranges. Ranges are added, edited, and deleted the same way as described above.

Restrict system provider access

When enabled, the system provider cannot sign in to your tenant's applications with the sys: login prefix; any attempt is refused with a generic Access Denied message. When disabled (the default), the system provider can sign in with the sys: prefix.

< Previous | Next >