The devices list & tenant separation
A device is one SIP account — one phone, softphone or trunk. This page covers the devices list and a rule new in v2.2.6: a customer's phones can only dial that customer's own extensions.
Open Devices
In the sidebar, go to Customers > Devices. The list shows every device: its online dot, name, type, extension, owning user, host and status, with quick actions on the right (call history, forwards, recordings, info, edit, hide, delete).
From here you can also see Hidden devices, run a Weak passwords check, view all Forwards across every device, Move a device to a different user, or Bulk creation for several devices at once. Click a row's edit icon (or Create device) to open a single device.
| Column | Meaning |
|---|---|
Online | A filled dot if the device is currently registered with Asterisk. |
Name | The device's short name — often the same as the extension, plus a description underneath if one is set. |
Type | SIP or IAX2. |
Extension | The internal number other devices, ring groups and IVR menus use to reach this phone. |
User | The customer (user account) this device belongs to and is billed under. |
Host | dynamic for a phone that registers itself, or a fixed host/IP for a static device or trunk. |
Tenant separation — new in v2.2.6
Before v2.2.6, every device on the system shared one dial plan: any phone could dial any other phone's extension, even across different customers, just by knowing the number. Since v2.2.6, each customer is walled off: a phone can only dial its own customer's extensions. A device belonging to Demo Company cannot reach a device belonging to a different customer by dialling its extension — the call simply does not connect.
Open a device and look at the Context field on the General tab. Its hint line, Effective endpoint context, shows the actual dial-plan context this device will use once saved — this is the wall in practice, not just a setting.
There is one planned exception: devices whose customers are explicitly put in the same PBX pool can reach each other, on purpose — see PBX pools & extensions. Outside of a shared pool, the wall always applies. Whether the wall is switched on at all is an operator-level setting, not something changed from this page.
Leave the Context field empty unless you have a specific reason to override it — empty means "the normal, internal context for this device's owner", which is what tenant separation relies on. This field is only shown to staff roles (admin, accountant, reseller, partner); a reseller cannot see or change the context of a device outside their own scope.
Check
Open a device and confirm its Effective endpoint context hint names a context for its own owner (not a shared, flat one). Two devices belonging to two different customers should not be able to dial each other's extensions — unless both customers are in the same PBX pool.