Log inSign up
Home
Webex Compliance
  • Overview

Webex Compliance

Compliance Officer & Data Access

Compliance Officers can access and manage organization content with dedicated authorization scopes. Learn how data ownership, room permissions, and meeting recordings affect that access.

anchorWebex Data

anchor
Permissions & Ownership

Data created within Webex belongs to the organization that owns the room (space). The owner of a group room is generally the organization for the person who created the room. For 1:1 rooms between users in different organizations, the organization that each person belongs to owns their participant’s content. Rooms created by bots are owned by the organization of the first non-bot participant.

Data access permissions within Webex vary depending on a few factors: the room creator, room membership, and organization membership. When a room is created, the organization associated with the creator is considered the owning organization for the room. If users from other organizations are added to the room, those organizations are participating organizations in the room.

In general, the following types of users will be viewing, creating, and managing data within Webex:

  • Room participants—can send and view messages within the room.
  • Room moderator—users can be assigned as a moderator by a room owner and have exclusive control of the room including the room’s title and participant list.
  • Compliance officers for the owning organization—can monitor and manage all data within group rooms created by a member of the organization; can manage all content in 1:1 rooms, including those with external participants.
  • Compliance officers for the participating organization-can monitor and manage data created by their users in rooms owned by another organization; can manage all content in 1:1 rooms with external participants.

In a 1:1 room between users of different organizations, either organization’s compliance officers can monitor and manage data created by both participants.

Security & Privacy

A key management server (KMS) is responsible for the creation and security of the encryption keys the Webex clients use to encrypt and decrypt data and communications. It is architecturally and operationally separated from the rest of the Webex Cloud and its data is not accessible by any other components. Whether the KMS is managed by Cisco or installed and managed on-premise, data within the Webex Cloud is encrypted from end-to-end and is not decrypted until it reaches the API endpoint.

For more information about data security and privacy in Webex, please see the Webex Security White Paper.

anchorCompliance

anchor
Compliance Officer

The role of a compliance officer is to ensure that a company is conducting its business in full compliance with all laws and regulations that pertain to its particular industry, as well as professional standards, accepted business practices, and internal standards.

The Webex REST API has compliance authorization scopes that support the compliance officer’s role. Using these spark-compliance scopes, compliance officers will have access to, and the ability to manage, all data created by their organization such as messages or content attachments. Compliance officers can monitor data and take action to mitigate compliance issues that could arise.

Authorization Scopes

The spark-compliance scopes and their descriptions are listed below:

Scope
Usage
spark-compliance:events_read
Access to read events in your user's organization
spark-compliance:messages_write
Delete messages in all spaces in your user's organization
spark-compliance:messages_read
Access to read messages in your user's organization
spark-compliance:recordings_write
Access to update/delete converged recording resources in your user’s organization
spark-compliance:recordings_read
Access to read converged recording resources in your user’s organization.
spark-compliance:memberships_write
Access to create/update/delete memberships in your user's organization
spark-compliance:memberships_read
Access to read memberships in your user's organization
spark-compliance:rooms_write
Access to modify rooms in your user's organization
spark-compliance:rooms_read
Access to read rooms in your user's organization
spark-compliance:teams_read
Access to read teams in your user's organization
spark-compliance:team_memberships_write
Access to update team memberships in your user's organization
spark-compliance:team_memberships_read
Access to read team memberships in your user's organization

For instructions on how to add these scopes to your app and for a full list of all available authorization scopes see the Integrations/OAuth Guide.

Using the Compliance Scopes

Normally, Webex REST API users only have access to information related to their account, such as messages in rooms where they are members. The spark-compliance scopes provide access to information across the organization. For instance, if granted the spark-compliance:messages_read scope, messages will be available for all rooms within the organization, not just those that the authenticated compliance officer is a member of.

Several scopes provide access to write data or take action within an organization. If an action should be taken against certain data within Webex for compliance reasons, the Webex REST API can be used with an authentication token authorized with one of the above scopes to carry out the action. For example, if a message needs to be deleted, the spark-compliance:messages_write scope will be required. To delete the message, use the DELETE /messages endpoint. Similarly, if a member of a room, either a person or a bot, needs to be added or removed, the spark-compliance:memberships_write scope will be required and the membership can be deleted with the DELETE /memberships endpoint.

When using the appropriate spark-compliance: scopes and API endpoints, the authenticated user does not need to be a member of the room to take action. For example, a compliance officer who is not a member of a particular room can create, update, or delete the room's memberships with the spark-compliance:memberships_write scope.

anchorMeetings

anchor

Please refer to the Meetings documentation for details.

Meeting Recordings

Compliance officers are able to retrieve user recordings for analysis and compliance. There is a separate API endpoint for admins and compliance officers /admin/recordings, while regular users use /recordings. As it relates to recording deletion, a recycle bin and associated recording status is available. A user typically moves a recording to the recycle bin via the GUI and then either restores the recording or purges the recording from the recycle bin. Once purged, the recording isn't accessible to regular users any longer, but it is still accessible to the Compliance Officer until it is removed through the retention process. Compliance officers who want to retrieve user-deleted recordings must query the /events API for deleted recording events, and use the returned recording ID to retrieve the recording from /recordings/{id}. Regular users will see a 404 error.

In This Article
  • Webex Data
  • Compliance
  • Meetings

Connect

Support

Developer Community

Developer Events

Contact Sales

Handy Links

Webex Ambassadors

Webex App Hub

Resources

Open Source Bot Starter Kits

Download Webex

DevNet Learning Labs

Terms of Service

Privacy Policy

Cookie Policy

Trademarks

© 2026 Cisco and/or its affiliates. All rights reserved.