Business Messaging: Access, Roles & Permissions Across Platforms
TL;DR
Every major messaging platform gates business access differently. The single most important difference is who holds the technical keys: some platforms (Apple, Google RCS, KakaoTalk, Viber) require an approved intermediary you cannot bypass, while others (Telegram, LINE, WhatsApp, Zalo) let a business hold its own API credentials. Role models range from granular named matrices (WhatsApp, LINE, Zalo) to almost none (Telegram, where possessing the token is control). Asian platforms additionally gate account creation on a registered legal entity.
On this page
What this compares
When a business wants to message customers on a given platform, three governance questions decide how much work — and how much dependency — is involved:
- Who can own the account, and what legal identity or verification is required.
- What roles exist inside it — who can send, who can manage settings, who can add other people.
- Who holds the technical access — the API keys or tokens — the brand itself, or a mandatory intermediary.
This page compares those three across the major channels. It is a neutral reference: no platform here is endorsed or integrated, and the model each platform publishes is described as-is (where a platform documents no role hierarchy, that is stated rather than inferred).
Who holds the API keys — the load-bearing difference
The most consequential axis is whether a business can hold its own technical credentials or must route through an approved partner. It is a spectrum:
- Mandatory intermediary — the brand cannot self-serve. Apple Messages for Business requires an approved Messaging Service Provider (MSP); Google RCS for Business works through a certified RCS Solution Provider; KakaoTalk business messaging requires a Kakao-authorized agency and a Kakao-issued sender key; Viber Business Messages is applied for and operated through a partner.
- Optional intermediary — the brand may hold its own tokens or delegate. WhatsApp, Messenger and Instagram let a business run its own Meta app or hand a Tech Provider a scoped token. Zalo and LINE let the account owner mint and revoke their own API tokens. WeChat issues the brand an AppID/secret directly, though overseas brands often use an agency in practice.
- No intermediary at all — Telegram is the purest: a bot token is issued instantly and the brand holds it directly.
The table below summarizes all three axes.
| Platform | API access held by | Role model | Entity gate |
|---|---|---|---|
| Apple Messages for Business | Approved MSP (mandatory) | Admin / Member / Read-only | Brand approval |
| WhatsApp Business Platform | Brand or Tech Provider | Full / Partial + system users | Business verification |
| Facebook Messenger | Brand or Tech Provider | Portfolio + Page tasks | Business verification |
| Brand or Tech Provider | Inherits Meta Page model | Business verification | |
| Google RCS for Business | Solution Provider (partner) | Partner owner + tech contact | Brand verification |
| Telegram | Brand (token holder) | None — token is control | None |
| WeChat Official Account | Brand (often via agency) | Administrator + Operators | Business license |
| LINE Official Account | Channel owner (self) | Admin / Operator variants | Regional screening |
| KakaoTalk Biz Message | Authorized agency (mandatory) | Master / Manager + app roles | Business registration |
| Viber Business Messages | Partner / BSP (effectively req.) | Bot admin only | Brand verification |
| Zalo Official Account | Brand (OA owner) | Six named roles | Business license |
How role models differ
The maturity of the named-role model varies enormously:
- Granular, documented matrices. WhatsApp and the wider Meta platform separate Full control from Partial access, add Finance and integration permissions, and issue scoped system-user tokens. LINE runs two distinct consoles — a business console (Admin, Operator, and restricted operator variants) and a developer console (provider/channel roles). Zalo publishes six explicitly named roles, from Administrator down to Analyst and Customer care.
- Named, but no permission matrix. Apple (Administrator, Member, Read-only, plus three program contacts), WeChat (one Administrator plus Operators), and KakaoTalk (channel Master/Manager plus developer-app roles) name their roles without publishing a full rights table.
- Thin or token-based. Google RCS documents only a partner account owner and a technical contact; Viber publishes no role taxonomy at all and pushes team access onto the partner platform; Telegram has no organizational hierarchy — for bots, whoever holds the token has full control, and Telegram Business instead grants a connected bot a fine-grained, per-chat set of rights the account owner can revoke.
- Borrowed. Instagram has no messaging role model of its own — it inherits Meta's Page and Business Portfolio structure.
The legal-entity gate is an Asia constant
Western platforms generally verify a business but rarely block account creation on a registered legal entity. Asian platforms typically do:
- WeChat requires a Chinese business license for a mainland account; overseas businesses are restricted to a single verified Service Account.
- KakaoTalk business messaging requires a Korean business registration certificate, and foreign companies usually cannot self-verify — they work through a local agency.
- Zalo requires a Vietnamese business registration license for a verified Official Account; without one, an account is limited to advertising only.
- LINE requires passing regional business screening to earn a verified (searchable) account.
For a business operating across regions, this means the same "set up a messaging presence" task is a light branding step in one market and a local-entity, local-agency project in another.
Why it matters
These differences decide real things: how fast you can go live, whether you depend on a partner you cannot remove, who on your team can actually send a message, and whether you even qualify to open an account in a given market.
The practical takeaway is that "business messaging" is not one capability but a dozen different governance regimes. And once a business operates on more than one of them, the account models diverge but the conversations still belong to the same people — which is the problem a unified inbox exists to solve: one relationship per person, regardless of which channel's permission model the message arrived through.
The per-platform pages below go into each governance model in detail, with sources.
Frequently asked questions
Which business messaging platforms require a third-party provider?
Apple Messages for Business (an approved MSP), Google RCS for Business (a certified Solution Provider), KakaoTalk business messaging (a Kakao-authorized agency plus a sender key), and Viber Business Messages (a partner/BSP) cannot be self-served. WhatsApp, Messenger, Instagram, LINE, Zalo, WeChat and Telegram let a business hold its own credentials, though some are commonly run through partners anyway.
Which platform gives a business the most direct control?
Telegram. A bot token is issued instantly with no account verification, and the brand holds it directly — there is no intermediary and no organizational role hierarchy to navigate. The trade-off is that possession of the token is the entire access-control model.
Do I need a registered company to open a business messaging account?
On the Asian platforms, usually yes — WeChat, KakaoTalk and Zalo gate a full business account on a registered legal entity (a business license or registration certificate). Western platforms typically let you create an account and then verify the business to unlock higher limits, rather than blocking creation outright.
Related
What is Apple Messages for Business?
Apple Messages for Business is a channel that lets customers start a conversation with a verified company directly in the Messages app on their Apple devices. There is no separate Apple business chat app and no direct Apple API for brands — a company registers its brand with Apple, connects an Apple-approved Messaging Service Provider (MSP), and that provider carries messages between Apple and the company’s systems.
Read →What is a Unified Inbox?
A unified inbox consolidates conversations from multiple communication channels — messengers, email, and more — into a single interface, so you can triage, read, and reply across all of them without switching apps and without losing track of who said what.
Read →Telegram vs WhatsApp vs iMessage CRM
Deals rarely live on one messenger — Telegram for crypto, WhatsApp for international, iMessage for the US. A single-channel Telegram CRM misses two-thirds of your relationships. A multi-messenger CRM captures all three natively into one record. Pantheon does this today, in alpha.
Read →What is a Messenger-Native CRM?
A messenger-native CRM is a customer relationship management system built from the ground up around messaging apps — Telegram, WhatsApp, iMessage, and others — as the primary communication channel, rather than an email-first CRM with a chat plugin bolted on.
Read →Last updated